TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field. This vulnerability allows attackers to execute phishing attacks, external redirects, and arbitrary code.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-22T19:20:28

Updated: 2022-07-10T20:19:09

Reserved: 2020-08-13T00:00:00


Link: CVE-2020-23050

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-22T20:15:10.370

Modified: 2022-11-05T02:05:27.093


Link: CVE-2020-23050

JSON object: View

cve-icon Redhat Information

No data.

CWE