A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1891016 Exploit Issue Tracking Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-28T10:20:26

Updated: 2021-05-28T10:20:26

Reserved: 2020-09-16T00:00:00


Link: CVE-2020-25715

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-28T11:15:07.640

Modified: 2021-06-08T02:10:20.387


Link: CVE-2020-25715

JSON object: View

cve-icon Redhat Information

No data.

CWE