A cross-site scripting (XSS) issue... CVE-2020-26517

3.5 AV AC AU C I A
发布: 2021-06-08
修订: 2024-11-21

A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application configuration (Admin only).

0%
暂无可用Exp或PoC
当前有24条受影响产品信息