ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-11987”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-11987
Published
2021-02-24
CVSS:
8.2
ShadowTrackr CVSS:
6.9
Summary:
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.