Vulnerability Description
Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yellowfinbi | Business Intelligence | 7.3 |
Related Weaknesses (CWE)
References
- https://github.com/Deepak983/CVE-2020-19586/blob/main/Stored%20XSS%20in%20MIAdmiExploitThird Party Advisory
- https://github.com/Deepak983/CVE-2020-19586/blob/main/Stored%20XSS%20in%20MIAdmiExploitThird Party Advisory
FAQ
What is CVE-2020-19586?
CVE-2020-19586 is a vulnerability with a CVSS score of 9.0 (CRITICAL). Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
How severe is CVE-2020-19586?
CVE-2020-19586 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-19586?
Check the references section above for vendor advisories and patch information. Affected products include: Yellowfinbi Business Intelligence.