Stored XSS Vulnerability in Archer by RSA Security
CVE-2020-29535
5.3MEDIUM
Summary
The affected version of Archer contains a stored XSS vulnerability that could be exploited by a remote authenticated user. This allows attackers to introduce malicious HTML or JavaScript code into a trusted application data store. When legitimate users access this corrupted data, their web browsers may execute the injected code within the context of the Archer application, potentially compromising sensitive information and functionality.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved