CVE-2020-7110Cross-site Scripting in Clearpass

Severity
4.8MEDIUMNVD
EPSS
0.3%
top 44.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 24

Description

ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save malicious scripts within ClearPass that could be executed resulting in a privilege escalation attack. Resolution: Fixed in 6.7.13, 6.8.4, 6.9.0 and higher.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

Affected Packages2 packages

NVDarubanetworks/clearpass6.7.06.7.13+1
CVEListV5arubanetworks/clearpass_policy_managerClearPass 6.8.x prior to 6.8.5 ClearPass 6.7.x prior to 6.7.13

🔴Vulnerability Details

2
GHSA
GHSA-qhw5-55vv-fxcp: ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save maliciou2022-05-24
CVEList
CVE-2020-7110: ClearPass is vulnerable to Stored Cross Site Scripting by allowing a malicious administrator, or a compromised administrator account, to save maliciou2020-04-16
CVE-2020-7110 — Cross-site Scripting in Clearpass | cvebase