Vulnerability Description
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spiceworks | Spiceworks | <= 7.5.00107 |
Related Weaknesses (CWE)
References
- http://spiceworks.comVendor Advisory
- https://abuyv.comThird Party Advisory
- https://abuyv.com/cve/spiceworks-stored-xssExploitThird Party Advisory
- http://spiceworks.comVendor Advisory
- https://abuyv.comThird Party Advisory
- https://abuyv.com/cve/spiceworks-stored-xssExploitThird Party Advisory
FAQ
What is CVE-2020-23450?
CVE-2020-23450 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitiza...
How severe is CVE-2020-23450?
CVE-2020-23450 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23450?
Check the references section above for vendor advisories and patch information. Affected products include: Spiceworks Spiceworks.