CVE-2020-37018
⚪ Do wiadomości
W GOautodial 4.0 występuje podatność na XSS, umożliwiająca wstrzykiwanie złośliwych skryptów.
CVSS
6.4
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.4 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-01-29 15:16:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 08:10:00 UTC |