Reflected XSS Vulnerability in Extreme Management Center by Extreme Networks
CVE-2020-16847

6.1MEDIUM

Key Information:

Vendor
CVE Published:
4 August 2020

What is CVE-2020-16847?

Extreme Management Center prior to version 8.5.0.169 is vulnerable to a reflected Cross-Site Scripting (XSS) attack. This vulnerability allows an unauthenticated attacker to execute arbitrary scripts in the context of a user's session when a maliciously crafted GET request is made. By exploiting this weakness, attackers can potentially compromise sensitive data, hijack user sessions, and perform actions on behalf of the user, ultimately undermining the security of web applications and systems.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.