PT-2020-4725 · Vmware · Vmware Horizon Server

Published

2020-10-22

·

Updated

2020-10-30

·

CVE-2020-3997

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: VMware Horizon Server versions prior to 7.10.3 or 7.13.0
Description: The issue is related to a lack of input data sanitization, which may allow an attacker to inject malicious scripts. Successful exploitation of this issue may enable an attacker to perform cross-site scripting attacks.
Recommendations: For versions prior to 7.10.3, update to version 7.10.3 or later. For versions prior to 7.13.0, update to version 7.13.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05277
CVE-2020-3997

Affected Products

Vmware Horizon Server