cbcvebase.
CVE-2020-10778
published 2020-08-11

CVE-2020-10778: In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is…

PriorityP427medium6CVSS 3.1
AVNACLPRHUINSUCHILAL
EPSS
0.88%
54.8th percentile
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate the expected behavior.

Affected

3 ranges
VendorProductVersion rangeFixed in
redhatcloudforms
redhatcloudforms
redhatcloudforms

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.