Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-12677


An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0 prior to 2018.0.3, 2018 SP1 - 2018.2 prior to 2018.2.3, 2018 SP2 - 2018.3 prior to 2018.3.7, 2019 - 2019.0 prior to 2019.0.3, 2019.1 - 2019.1 prior to 2019.1.2, and 2019.2 - 2019.2 prior to 2019.2.2.


Published

2020-05-14T18:15:12.173

Last Modified

2024-11-21T05:00:03.357

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress moveit_automation < 2018.0.3 Yes
Application progress moveit_automation < 2018.2.3 Yes
Application progress moveit_automation < 2018.3.7 Yes
Application progress moveit_automation < 2019.0.3 Yes
Application progress moveit_automation < 2019.1.2 Yes
Application progress moveit_automation < 2019.2.2 Yes

References