CVE-2020-22158
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
14/09/2020
Last modified:
12/11/2020
Description
MediaKind (formerly Ericsson) RX8200 5.13.3 devices are vulnerable to multiple reflected and stored XSS. An attacker has to inject JavaScript code directly in the "path" or "Services+ID" parameters and send the URL to a user in order to exploit reflected XSS. In the case of stored XSS, an attacker must modify the "name" parameter with the malicious code.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mediakind:rx8200_firmware:5.13.3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediakind:rx8200:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



