Stored XSS Vulnerability in JetBrains Space
CVE-2020-11416

5.4MEDIUM

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
22 April 2020

Summary

JetBrains Space, prior to the version released on April 22, 2020, is subject to a stored Cross-Site Scripting (XSS) vulnerability that occurs in its chat functionality. This vulnerability could allow an attacker to embed malicious scripts within chat messages, which may then execute in the browser of any user viewing the chat, leading to potential data theft, session hijacking, or other malicious actions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.