Vulnerability Description
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Enterprise Network Disk | 6.1 |
Related Weaknesses (CWE)
References
- https://iknow.lenovo.com.cn/detail/dc_191492.htmlThird Party Advisory
- https://iknow.lenovo.com.cn/detail/dc_191492.htmlThird Party Advisory
FAQ
What is CVE-2020-8348?
CVE-2020-8348 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's ...
How severe is CVE-2020-8348?
CVE-2020-8348 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8348?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Enterprise Network Disk.