Stored XSS Vulnerability in JetBrains Space
CVE-2020-11416
5.4MEDIUM
Summary
JetBrains Space, prior to the version released on April 22, 2020, is subject to a stored Cross-Site Scripting (XSS) vulnerability that occurs in its chat functionality. This vulnerability could allow an attacker to embed malicious scripts within chat messages, which may then execute in the browser of any user viewing the chat, leading to potential data theft, session hijacking, or other malicious actions.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved