Vulnerability Description
A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application configuration (Admin only).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intland | Codebeamer | 10.0.0 |
Related Weaknesses (CWE)
References
- https://intland.com/codebeamer/application-lifecycle-management/Vendor Advisory
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-10_CSNC-2020ExploitThird Party Advisory
- https://intland.com/codebeamer/application-lifecycle-management/Vendor Advisory
- https://www.compass-security.com/fileadmin/Research/Advisories/2021-10_CSNC-2020ExploitThird Party Advisory
FAQ
What is CVE-2020-26517?
CVE-2020-26517 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a pro...
How severe is CVE-2020-26517?
CVE-2020-26517 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26517?
Check the references section above for vendor advisories and patch information. Affected products include: Intland Codebeamer.