CVE-2010-2088

Severity
4.3MEDIUM
EPSS
11.9%
top 6.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 27
Latest updateMay 17

Description

ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWSTATE parameter.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-7w44-3x7p-5w78: ASP2022-05-17
CVEList
CVE-2010-2088: ASP2010-05-27
CVE-2010-2088 (MEDIUM CVSS 4.3) | ASP.NET in Microsoft .NET 3.5 does | cvebase.io