ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-19202”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-19202
Published
2021-06-17
CVSS:
5.4
ShadowTrackr CVSS:
0.4
Summary:
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" parameter in IPFire 2.21 (x86_64) - Core Update 130. It allows an authenticated WebGUI user with privileges to execute Stored Cross-site Scripting in the Captive Portal page.