A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.secomea.com/support/cybersecurity-advisory/#3042 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: Secomea
Published: 2021-02-16T15:45:49.213443Z
Updated: 2024-09-16T16:17:30.588Z
Reserved: 2020-11-24T00:00:00
Link: CVE-2020-29025
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-02-16T16:15:12.893
Modified: 2024-11-21T05:23:32.650
Link: CVE-2020-29025
Redhat
No data.