CVEs Blog | G5 Cyber Security

CVE-2020-25104 – eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted file

eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25104

Reference (s):

Exit mobile version