CVE-2020-4775

Severity
5.4MEDIUM
EPSS
0.1%
top 70.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 12
Latest updateMay 24

Description

A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. This vulnerability allows attackers to inject malicious scripts into web applications for the purpose of running unwanted actions on the end user's device, restricted to a single location. IBM X-Force ID: 189153.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDibm/curam_social_program_management7.0.10.0, 7.0.9.0+1
CVEListV5ibm/curam_spm7.0.10, 7.0.9+1

🔴Vulnerability Details

2
GHSA
GHSA-rpc3-5m2x-2w73: A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 72022-05-24
CVEList
CVE-2020-4775: A cross-site scripting (XSS) vulnerability may impact IBM Curam Social Program Management 72020-10-12
CVE-2020-4775 (MEDIUM CVSS 5.4) | A cross-site scripting (XSS) vulner | cvebase.io