Vulnerability Description
Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Versiant | Lynx Customer Service Portal | 3.5.2 |
Related Weaknesses (CWE)
References
- https://csp.poha.com/lynx/Permissions Required
- https://kb.cert.org/vuls/id/962085/Third Party AdvisoryUS Government Resource
- https://csp.poha.com/lynx/Permissions Required
- https://kb.cert.org/vuls/id/962085/Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-9055?
CVE-2020-9055 is a vulnerability with a CVSS score of 3.9 (LOW). Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is store...
How severe is CVE-2020-9055?
CVE-2020-9055 has been rated LOW with a CVSS base score of 3.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9055?
Check the references section above for vendor advisories and patch information. Affected products include: Versiant Lynx Customer Service Portal.