Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.
References
Link Resource
https://csp.poha.com/lynx/ Permissions Required
https://kb.cert.org/vuls/id/962085/ Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: certcc

Published: 2019-04-12T00:00:00

Updated: 2020-03-30T20:50:27

Reserved: 2020-02-18T00:00:00


Link: CVE-2020-9055

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-03-30T22:15:15.667

Modified: 2020-04-01T18:27:42.210


Link: CVE-2020-9055

JSON object: View

cve-icon Redhat Information

No data.

CWE