Vulnerability Description
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Vibe | < 4.0.7 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2020/Mar/50
- https://softwaresupport.softwaregrp.com/doc/KM03630475
- http://seclists.org/fulldisclosure/2020/Mar/50
- https://softwaresupport.softwaregrp.com/doc/KM03630475
FAQ
What is CVE-2020-9520?
CVE-2020-9520 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vib...
How severe is CVE-2020-9520?
CVE-2020-9520 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9520?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Vibe.