ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-11988”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-11988
Published
2021-02-24
CVSS:
8.2
ShadowTrackr CVSS:
4.8
Summary:
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.