Vulnerability Description
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field. This vulnerability allows attackers to execute phishing attacks, external redirects, and arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Taotesting | Tao Assessment Platform | 3.3.0 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/79.htmlTechnical Description
- https://www.vulnerability-lab.com/get_content.php?id=2215ExploitThird Party Advisory
- https://cwe.mitre.org/data/definitions/79.htmlTechnical Description
- https://www.vulnerability-lab.com/get_content.php?id=2215ExploitThird Party Advisory
FAQ
What is CVE-2020-23050?
CVE-2020-23050 is a vulnerability with a CVSS score of 8.0 (HIGH). TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field. This vulnerability allows attac...
How severe is CVE-2020-23050?
CVE-2020-23050 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23050?
Check the references section above for vendor advisories and patch information. Affected products include: Taotesting Tao Assessment Platform.