6.1

CVE-2020-13168

Exploit
SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SysaidSysaid On-premises Version5.0
SysaidSysaid On-premises Version5.5.06
SysaidSysaid On-premises Version5.6
SysaidSysaid On-premises Version6.0.9
SysaidSysaid On-premises Version6.5
SysaidSysaid On-premises Version7.0
SysaidSysaid On-premises Version7.5
SysaidSysaid On-premises Version8.0
SysaidSysaid On-premises Version8.1
SysaidSysaid On-premises Version8.5
SysaidSysaid On-premises Version9.0.10
SysaidSysaid On-premises Version9.0.30
SysaidSysaid On-premises Version9.0.40
SysaidSysaid On-premises Version9.0.52
SysaidSysaid On-premises Version9.0.53
SysaidSysaid On-premises Version9.1.0
SysaidSysaid On-premises Version14.1
SysaidSysaid On-premises Version14.2
SysaidSysaid On-premises Version14.3
SysaidSysaid On-premises Version14.4.00
SysaidSysaid On-premises Version14.4.1
SysaidSysaid On-premises Version14.4.2
SysaidSysaid On-premises Version14.4.3
SysaidSysaid On-premises Version15.1.20
SysaidSysaid On-premises Version15.1.30
SysaidSysaid On-premises Version15.1.50
SysaidSysaid On-premises Version15.1.70
SysaidSysaid On-premises Version15.2.03
SysaidSysaid On-premises Version15.2.04
SysaidSysaid On-premises Version15.2.05
SysaidSysaid On-premises Version16.3.16
SysaidSysaid On-premises Version16.3.17
SysaidSysaid On-premises Version17.2.03
SysaidSysaid On-premises Version17.3.57
SysaidSysaid On-premises Version18.1.54
SysaidSysaid On-premises Version19.2
SysaidSysaid On-premises Version19.4
SysaidSysaidsy On-premises Version20.1.11 Updateb26
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.664
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.