{ "id": "CVE-2020-28409", "sourceIdentifier": "cve@mitre.org", "published": "2020-11-10T21:15:13.487", "lastModified": "2020-11-18T19:05:44.780", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur." }, { "lang": "es", "value": "El servidor en Dundas BI versiones hasta 8.0.0.1001, permite un ataque de tipo XSS por medio de la adici\u00f3n de un Componente (por ejemplo, un bot\u00f3n) cuando ocurren eventos como hacer clic, desplazarse, etc" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 5.4, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.3, "impactScore": 2.7 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "SINGLE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 3.5 }, "baseSeverity": "LOW", "exploitabilityScore": 6.8, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:dundas:dundas_bi:*:*:*:*:*:*:*:*", "versionEndIncluding": "8.0.0.1001", "matchCriteriaId": "0D9F3D49-03B0-42B8-8448-3BAA822698BE" } ] } ] } ], "references": [ { "url": "https://mattschmidt.net/2020/11/10/dundas-persistent-xss/", "source": "cve@mitre.org", "tags": [ "Exploit", "Third Party Advisory" ] } ] }