Stored Cross-Site Scripting Vulnerability in Code Insight by Flexera
CVE-2020-12082

5.4MEDIUM

Key Information:

Vendor

Flexera

Vendor
CVE Published:
17 September 2021

What is CVE-2020-12082?

A stored cross-site scripting issue exists in the Web UI of Flexera's Code Insight, affecting versions up to and including 2020 R1. This vulnerability allows an attacker to inject malicious scripts into the affected areas of the web interface. Consequently, when users interact with compromised elements, their browsers may execute the injected scripts. This can lead to sensitive data exposure and unauthorized actions performed on behalf of the users.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.