touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. The issue is patched in version 2.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-18840 touchbase.ai before version 2.0 is vulnerable to Cross-Site Scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action. The issue is patched in version 2.0.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T15:49:07.286Z

Reserved: 2020-10-01T00:00:00

Link: CVE-2020-26221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-11T23:15:11.743

Modified: 2024-11-21T05:19:34.250

Link: CVE-2020-26221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.