Advertisement






Apache OpenMeetings 3.1.0 Cross Site Scripting

CVE Category Price Severity
CVE-2020-13934 CWE-79 $300 High
Author Risk Exploitation Type Date
Unknown High Remote 2016-08-13
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N 0.31523 0.50264

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2016080119

Below is a copy:

Apache OpenMeetings 3.1.0 Cross Site ScriptingSeverity: Moderate

Vendor: The Apache Software Foundation

Versions Affected: Apache OpenMeetings 3.1.0

Description: The value of the URL's "swf" query parameter is
interpolated into the JavaScript tag without being escaped, leading to
the reflected XSS.

All users are recommended to upgrade to Apache OpenMeetings 3.1.2

Credit: This issue was identified by Matthew Daley


Apache OpenMeetings Team


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum