On BIG-IP ASM 15.1.0-15.1.0.5, a cross-site scripting (XSS) vulnerability exists in the BIG-IP ASM Configuration utility response and blocking pages. An authenticated user with administrative privileges can specify a response page with any content, including JavaScript code that will be executed when preview is opened.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published: 2020-10-29T15:14:43

Updated: 2024-08-04T08:47:40.913Z

Reserved: 2020-01-06T00:00:00

Link: CVE-2020-5932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-10-29T16:15:15.447

Modified: 2020-11-09T03:08:36.017

Link: CVE-2020-5932

cve-icon Redhat

No data.