CVE-2020-25715Cross-site Scripting in Project Pki-core

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 41.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 28
Latest updateDec 10

Description

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5pki-core_project/pki-corepki-core 10.9.0

Patches

🔴Vulnerability Details

4
OSV
dogtag-pki vulnerabilities2024-12-10
GHSA
GHSA-cg99-xqcm-67pf: A flaw was found in pki-core 102022-05-24
OSV
CVE-2020-25715: A flaw was found in pki-core 102021-05-28
CVEList
CVE-2020-25715: A flaw was found in pki-core 102021-05-28

📋Vendor Advisories

3
Ubuntu
Dogtag PKI vulnerabilities2024-12-10
Red Hat
pki-core: XSS in the certificate search results2021-03-02
Debian
CVE-2020-25715: dogtag-pki - A flaw was found in pki-core 10.9.0. A specially crafted POST request can be use...2020

💬Community

1
Bugzilla
CVE-2020-25715 pki-core: XSS in the certificate search results2020-10-23
CVE-2020-25715 — Cross-site Scripting | cvebase