6.1
CVSSv3

CVE-2020-14294

Published: 02/10/2020 Updated: 08/10/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Secudos Qiata FTA 1.70.19. The comment feature allows persistent XSS that is executed when reading transfer comments or the global notice board.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

secudos qiata fta

Exploits

Qiata FTA versions 17019 and below suffer from a cross site scripting vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [SYSS-2020-024] Qiata FTA - Persistent Cross-Site Scripting <!--X-Subject-Header-End--> <!--X-Head-of-Message--> Fro ...

Github Repositories

This repository holds the advisory of the CVE-2020-14294

CVE-2020-14294 This vulnerablity was discovered and disclosed by me This repository will hold the advisory This repository is only for educational purposes Links Advisory SYSS-2020-024 Detailed writeup SySS Blog entry Vendor notice MITRE Entry NVD Entry