383
VMScore

CVE-2020-14333

Published: 18/08/2020 Updated: 12/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A flaw was found in Ovirt Engine's web interface in ovirt 4.4 and previous versions, where it did not filter user-controllable parameters completely, resulting in a reflected cross-site scripting attack. This flaw allows an malicious user to leverage a phishing attack, steal an unsuspecting user's cookies or other confidential information, or impersonate them within the application's context.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ovirt ovirt-engine

Vendor Advisories

Synopsis Moderate: Red Hat Virtualization security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat Virtualization Engine 44Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability ...