// For flags

CVE-2020-12677

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0 prior to 2018.0.3, 2018 SP1 - 2018.2 prior to 2018.2.3, 2018 SP2 - 2018.3 prior to 2018.3.7, 2019 - 2019.0 prior to 2019.0.3, 2019.1 - 2019.1 prior to 2019.1.2, and 2019.2 - 2019.2 prior to 2019.2.2.

Se detectó un problema en Progress MOVEit Automation Web Admin. Un endpoint de la aplicación Web Admin no pudo sanear adecuadamente una entrada maliciosa, lo que podría permitir a un atacante no autenticado ejecutar código arbitrario en el navegador de una víctima, también se conoce como vulnerabilidad de tipo XSS. Esto afecta a versiones 2018 - versiones 2018.0 anteriores a 2018.0.3, 2018 SP1 - versiones 2018.2 anteriores a 2018.2.3, 2018 SP2 - versiones 2018.3 anteriores a 2018.3.7, 2019 - versiones 2019.0 anteriores a 2019.0.3, 2019.1 - versiones 2019.1 anteriores a 2019.1.2, y 2019.2 - versiones 2019.2 anteriores a 2019.2.2.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-05-06 CVE Reserved
  • 2020-05-14 CVE Published
  • 2023-10-02 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress
Search vendor "Progress"
Moveit Automation
Search vendor "Progress" for product "Moveit Automation"
>= 2018.0 < 2018.0.3
Search vendor "Progress" for product "Moveit Automation" and version " >= 2018.0 < 2018.0.3"
-
Affected
Progress
Search vendor "Progress"
Moveit Automation
Search vendor "Progress" for product "Moveit Automation"
>= 2018.2 < 2018.2.3
Search vendor "Progress" for product "Moveit Automation" and version " >= 2018.2 < 2018.2.3"
-
Affected
Progress
Search vendor "Progress"
Moveit Automation
Search vendor "Progress" for product "Moveit Automation"
>= 2018.3 < 2018.3.7
Search vendor "Progress" for product "Moveit Automation" and version " >= 2018.3 < 2018.3.7"
-
Affected
Progress
Search vendor "Progress"
Moveit Automation
Search vendor "Progress" for product "Moveit Automation"
>= 2019.0 < 2019.0.3
Search vendor "Progress" for product "Moveit Automation" and version " >= 2019.0 < 2019.0.3"
-
Affected
Progress
Search vendor "Progress"
Moveit Automation
Search vendor "Progress" for product "Moveit Automation"
>= 2019.1 < 2019.1.2
Search vendor "Progress" for product "Moveit Automation" and version " >= 2019.1 < 2019.1.2"
-
Affected
Progress
Search vendor "Progress"
Moveit Automation
Search vendor "Progress" for product "Moveit Automation"
>= 2019.2 < 2019.2.2
Search vendor "Progress" for product "Moveit Automation" and version " >= 2019.2 < 2019.2.2"
-
Affected