Filtered by vendor Jenkins Subscriptions
Filtered by product Vncrecorder Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-2206 1 Jenkins 1 Vncrecorder 2024-11-21 6.1 Medium
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
CVE-2020-2205 1 Jenkins 1 Vncrecorder 2024-11-21 4.8 Medium
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators.