CVE-2020-12677
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0 prior to 2018.0.3, 2018 SP1 - 2018.2 prior to 2018.2.3, 2018 SP2 - 2018.3 prior to 2018.3.7, 2019 - 2019.0 prior to 2019.0.3, 2019.1 - 2019.1 prior to 2019.1.2, and 2019.2 - 2019.2 prior to 2019.2.2.
Se detectó un problema en Progress MOVEit Automation Web Admin. Un endpoint de la aplicación Web Admin no pudo sanear adecuadamente una entrada maliciosa, lo que podría permitir a un atacante no autenticado ejecutar código arbitrario en el navegador de una víctima, también se conoce como vulnerabilidad de tipo XSS. Esto afecta a versiones 2018 - versiones 2018.0 anteriores a 2018.0.3, 2018 SP1 - versiones 2018.2 anteriores a 2018.2.3, 2018 SP2 - versiones 2018.3 anteriores a 2018.3.7, 2019 - versiones 2019.0 anteriores a 2019.0.3, 2019.1 - versiones 2019.1 anteriores a 2019.1.2, y 2019.2 - versiones 2019.2 anteriores a 2019.2.2.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-06 CVE Reserved
- 2020-05-14 CVE Published
- 2023-10-02 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.progress.com/s/article/MOVEit-Automation-Cross-Site-Scripting-Vulnerability-XSS-May-2020 | 2020-05-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Moveit Automation Search vendor "Progress" for product "Moveit Automation" | >= 2018.0 < 2018.0.3 Search vendor "Progress" for product "Moveit Automation" and version " >= 2018.0 < 2018.0.3" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Automation Search vendor "Progress" for product "Moveit Automation" | >= 2018.2 < 2018.2.3 Search vendor "Progress" for product "Moveit Automation" and version " >= 2018.2 < 2018.2.3" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Automation Search vendor "Progress" for product "Moveit Automation" | >= 2018.3 < 2018.3.7 Search vendor "Progress" for product "Moveit Automation" and version " >= 2018.3 < 2018.3.7" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Automation Search vendor "Progress" for product "Moveit Automation" | >= 2019.0 < 2019.0.3 Search vendor "Progress" for product "Moveit Automation" and version " >= 2019.0 < 2019.0.3" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Automation Search vendor "Progress" for product "Moveit Automation" | >= 2019.1 < 2019.1.2 Search vendor "Progress" for product "Moveit Automation" and version " >= 2019.1 < 2019.1.2" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Moveit Automation Search vendor "Progress" for product "Moveit Automation" | >= 2019.2 < 2019.2.2 Search vendor "Progress" for product "Moveit Automation" and version " >= 2019.2 < 2019.2.2" | - |
Affected
|