CVE-2020-13168

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/10/2020
Last modified:
08/10/2020

Description

SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sysaid:sysaid_on-premises:5.0:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:5.5.06:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:5.6:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:6.0.9:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:6.5:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:7.0:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:7.5:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:8.0:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:8.1:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:8.5:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:9.0.10:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:9.0.30:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:9.0.40:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:9.0.52:*:*:*:*:*:*:*
cpe:2.3:a:sysaid:sysaid_on-premises:9.0.53:*:*:*:*:*:*:*