PT-2020-14732 · Immuta · Immuta

Chris Davis

·

Published

2020-11-05

·

Updated

2021-07-21

·

CVE-2020-15951

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Immuta version 2.8.2
Description The issue allows attackers to inject arbitrary HTML content into the application by supplying malicious project names. This could be used to redirect users to a phishing website in an attempt to steal credentials.
Recommendations For Immuta version 2.8.2, update to a version that properly sanitizes user-supplied input to prevent HTML injection attacks. As a temporary workaround, consider restricting user input for project names to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15951

Affected Products

Immuta