CVE-2020-36653

A vulnerability was found in GENI Portal. It has been rated as problematic. Affected by this issue is some unknown functionality of the file portal/www/portal/error-text.php. The manipulation of the argument error leads to cross site scripting. The attack may be launched remotely. The patch is identified as c2356cc41260551073bfaa3a94d1ab074f554938. It is recommended to apply a patch to fix this issue. VDB-218474 is the identifier assigned to this vulnerability.
References
Link Resource
https://github.com/GENI-NSF/geni-portal/commit/c2356cc41260551073bfaa3a94d1ab074f554938 Patch
https://github.com/GENI-NSF/geni-portal/pull/1822 Patch
https://vuldb.com/?ctiid.218474 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.218474 Permissions Required Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:geni:geni-portal:*:*:*:*:*:*:*:*

History

11 Apr 2024, 01:08

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en GENI Portal. Se ha clasificado como problemática. Una función desconocida del archivo portal/www/portal/error-text.php es afectada por esta vulnerabilidad. La manipulación del argumento error deriva en un cross site scripting. El ataque puede lanzarse de forma remota. El parche se identifica como c2356cc41260551073bfaa3a94d1ab074f554938. Se recomienda aplicar el parche para solucionar este problema. Se asgina el identificador VDB-218474 a esta vulnerabilidad.

29 Feb 2024, 01:28

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-18 08:15

Updated : 2024-05-17 01:48


NVD link : CVE-2020-36653

Mitre link : CVE-2020-36653

CVE.ORG link : CVE-2020-36653


JSON object : View

Products Affected

geni

  • geni-portal
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')