CVE-2020-28722
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
12/05/2021
Last modified:
19/05/2021
Description
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:deskpro:deskpro:*:*:*:*:cloud:*:*:* | 2020-07-30 (including) | 2020.2.3.48207 (including) |
cpe:2.3:a:deskpro:deskpro:*:*:*:*:on-premise:*:*:* | 2020-07-30 (including) | 2020.2.3.48207 (including) |
To consult the complete list of CPE names with products and versions, see this page