CVE-2020-5336

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
04/05/2020
Last modified:
07/05/2020

Description

RSA Archer, versions prior to 6.7 P1 (6.7.0.1), contain a URL injection vulnerability. An unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious JavaScript code on the affected system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:* 6.7.0.1 (excluding)