Home Embedded Vulns General Vulns

CVE-2020-1696

MEDIUM 4.6

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date March 20, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.

Potentially Affected Vendors