Vulnerability Description
Reflected Cross-Site Scripting (XSS) vulnerability in MONITORAPP WAF in which script can be executed when responding to Request URL information. It provides a function to response to Request URL information when blocking.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Monitorapp | Application Insight Web Application | <= 2020-06-16 |
| Monitorapp | Web Application Firewall | <= 2020-06-16 |
Related Weaknesses (CWE)
References
- https://github.com/kbgsft/vuln-AIWAF/wiki/Cross-site-scripting%28XSS%29-vulnerab
- https://github.com/monitorapp-aicc/report/wiki/CVE-2020-14210
- https://github.com/kbgsft/vuln-AIWAF/wiki/Cross-site-scripting%28XSS%29-vulnerab
- https://github.com/monitorapp-aicc/report/wiki/CVE-2020-14210
FAQ
What is CVE-2020-14210?
CVE-2020-14210 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Reflected Cross-Site Scripting (XSS) vulnerability in MONITORAPP WAF in which script can be executed when responding to Request URL information. It provides a function to response to Request URL infor...
How severe is CVE-2020-14210?
CVE-2020-14210 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-14210?
Check the references section above for vendor advisories and patch information. Affected products include: Monitorapp Application Insight Web Application, Monitorapp Web Application Firewall.