Stored XSS Vulnerability in Symmetricom SyncServer Devices
CVE-2020-9028
6.1MEDIUM
What is CVE-2020-9028?
Certain versions of Symmetricom SyncServer devices are vulnerable to a stored XSS attack, which can occur through the 'newUserName' parameter on the User Creation, Deletion, and Password Maintenance screen. An attacker can exploit this vulnerability to inject malicious scripts, potentially compromising the security of the device and permitting unauthorized access.