ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36905”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36905
Published
2026-01-06
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.