CVE-2020-21993
Summary
| CVE | CVE-2020-21993 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-28 15:15:00 UTC |
| Updated | 2021-05-05 20:25:00 UTC |
| Description | In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wems | Enterprise Manager | 2.19.7959 | All | All | All |
| Application | Wems | Enterprise Manager | 2.55.8782 | All | All | All |
| Application | Wems | Enterprise Manager | 2.55.8806 | All | All | All |
| Application | Wems | Enterprise Manager | 2.58.8903 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Science Lab » WEMS Enterprise Manager 2.58 (email) Reflected XSS | MISC | www.zeroscience.mk | |
| WEMS Enterprise Manager 2.58 Cross Site Scripting - CXSecurity.com | MISC | cxsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.