PT-2020-12550 · Webswing · Webswing

Published

2020-12-30

·

Updated

2021-07-21

·

CVE-2020-11103

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Webswing versions prior to 2.6.12 LTS Webswing versions 2.7.x Webswing versions 20.x prior to 20.1
Description JsLink in Webswing allows remote code execution.
Recommendations For Webswing versions prior to 2.6.12 LTS, update to version 2.6.12 LTS or later. For Webswing versions 2.7.x, update to version 20.1 or later. For Webswing versions 20.x prior to 20.1, update to version 20.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-11103

Affected Products

Webswing