A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-21407 | A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application. This issue affects all versions and variants of SM-E prior to version 9.3 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.secomea.com/support/cybersecurity-advisory/#3042 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Secomea
Published:
Updated: 2024-09-16T16:17:30.588Z
Reserved: 2020-11-24T00:00:00
Link: CVE-2020-29025
No data.
Status : Modified
Published: 2021-02-16T16:15:12.893
Modified: 2024-11-21T05:23:32.650
Link: CVE-2020-29025
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD