CVE-2020-3975
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
21/08/2020
Last modified:
26/08/2020
Description
VMware App Volumes 2.x prior to 2.18.6 and VMware App Volumes 4 prior to 2006 contain a Stored Cross-Site Scripting (XSS) vulnerability. A malicious actor with access to create and edit applications or create storage groups, may be able to inject malicious script which will be executed by a victim's browser when viewing.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:* | 2.0 (including) | 2.18.6 (excluding) |
cpe:2.3:a:vmware:app_volumes:*:*:*:*:*:*:*:* | 4 (including) | 2006 (excluding) |
To consult the complete list of CPE names with products and versions, see this page