6.5
CVSSv2

CVE-2020-10778

Published: 11/08/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 6 | Impact Score: 4.7 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cloudforms 4.7

redhat cloudforms 5.0.0

Vendor Advisories

Synopsis Critical: CloudForms 4716 security, bug fix and enhancement update Type/Severity Security Advisory: Critical Topic An update is now available for CloudForms Management Engine 510Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scorin ...
Synopsis Critical: CloudForms 507 bug fix and enhancement update Type/Severity Security Advisory: Critical Topic An update is now available for CloudForms Management Engine 511Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring System (C ...