CVE-2020-17457

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/03/2021
Last modified:
25/03/2021

Description

Fujitsu ServerView Suite iRMC before 9.62F allows XSS. An authenticated attacker can store an XSS payload in the PSCU_FILE_INIT field of a Save Configuration XML document. The payload is triggered in the HTTP error response pages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fujitsu:serverview_remote_management:*:*:*:*:*:*:*:* 9.62f (excluding)