CVE-2020-29535
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
Archer versiones anteriores a 6.8 P4 (6.8.0.4), contiene una vulnerabilidad de tipo XSS almacenado. Un usuario de Archer malicioso autenticado remoto podría explotar esta vulnerabilidad para almacenar código HTML o JavaScript malicioso en un almacén confiable de datos de aplicación. Cuando los usuarios de la aplicación acceden al almacén de datos corrupto por medio de sus navegadores, el código malicioso es ejecutado por el navegador web en el contexto de la aplicación web vulnerable
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-03 CVE Reserved
- 2021-01-29 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.rsa.com/docs/DOC-115223 | 2021-02-03 | |
https://www.rsa.com/en-us/company/vulnerability-response-policy | 2021-02-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.6 < 6.6.0.8 Search vendor "Rsa" for product "Archer" and version " >= 6.6 < 6.6.0.8" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.7 < 6.7.0.8 Search vendor "Rsa" for product "Archer" and version " >= 6.7 < 6.7.0.8" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.8 < 6.8.0.5 Search vendor "Rsa" for product "Archer" and version " >= 6.8 < 6.8.0.5" | - |
Affected
| ||||||
Rsa Search vendor "Rsa" | Archer Search vendor "Rsa" for product "Archer" | >= 6.9 < 6.9.0.1 Search vendor "Rsa" for product "Archer" and version " >= 6.9 < 6.9.0.1" | - |
Affected
|