{"api_version":"1","generated_at":"2026-07-23T15:32:46+00:00","cve":"CVE-2020-15263","urls":{"html":"https://cve.report/CVE-2020-15263","api":"https://cve.report/api/cve/CVE-2020-15263.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-15263","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-15263"},"summary":{"title":"CVE-2020-15263","description":"In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2020-10-19 21:15:00","updated_at":"2020-10-22 18:35:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/orchidsoftware/platform/commit/03f9a113b1a70bc5075ce86a918707f0e7d82169","name":"https://github.com/orchidsoftware/platform/commit/03f9a113b1a70bc5075ce86a918707f0e7d82169","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"refs #1313 Escape inline attributes (#1314) · orchidsoftware/platform@03f9a11 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/orchidsoftware/platform/security/advisories/GHSA-589w-hccm-265x","name":"https://github.com/orchidsoftware/platform/security/advisories/GHSA-589w-hccm-265x","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"Inline attribute values were not processed. · Advisory · orchidsoftware/platform · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-15263","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15263","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"15263","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orchid","cpe5":"platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"15263","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"orchid","cpe5":"platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2020-15263","STATE":"PUBLIC","TITLE":"XSS in platform"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"platform","version":{"version_data":[{"version_value":">= 9.0.0, < 9.4.4"}]}}]},"vendor_name":"orchidsoftware"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"{\"CWE-79\":\"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')\"}"}]}]},"references":{"reference_data":[{"name":"https://github.com/orchidsoftware/platform/security/advisories/GHSA-589w-hccm-265x","refsource":"CONFIRM","url":"https://github.com/orchidsoftware/platform/security/advisories/GHSA-589w-hccm-265x"},{"name":"https://github.com/orchidsoftware/platform/commit/03f9a113b1a70bc5075ce86a918707f0e7d82169","refsource":"MISC","url":"https://github.com/orchidsoftware/platform/commit/03f9a113b1a70bc5075ce86a918707f0e7d82169"}]},"source":{"advisory":"GHSA-589w-hccm-265x","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2020-10-19 21:15:00","lastModifiedDate":"2020-10-22 18:35:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:orchid:platform:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.4.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"15263","Ordinal":"176642","Title":"CVE-2020-15263","CVE":"CVE-2020-15263","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"15263","Ordinal":"1","NoteData":"In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"15263","Ordinal":"2","NoteData":"2020-10-19","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"15263","Ordinal":"3","NoteData":"2020-10-19","Type":"Other","Title":"Modified"}]}}}