Show plain JSON{"id": "CVE-2020-26733", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 3.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N", "authentication": "SINGLE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 5.4, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.3}]}, "published": "2021-01-14T16:15:17.787", "references": [{"url": "https://github.com/swzhouu/CVE-2020-26733", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://github.com/swzhouu/CVE-2020-26733", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS Configuration Section."}, {"lang": "es", "value": "Un ataque de tipo Cross Site Scripting (XSS) en la p\u00e1gina de Configuraci\u00f3n en SKYWORTH GN542VF Hardware Versi\u00f3n 2.0 y Software Versi\u00f3n 2.0.0.16, permite a un atacante autenticado inyectar su propio script en la p\u00e1gina por medio de la Secci\u00f3n de Configuraci\u00f3n DDNS"}], "lastModified": "2024-11-21T05:20:16.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:skyworth:gn542vf_firmware:2.0.0.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C292A10C-473F-41CF-B12A-B4F5039EC97F"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:skyworth:gn542vf:2.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "93AF8F37-188A-4CC6-B304-76A17C32BA1E"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org"}