Lucene search

K
cvelistMitreCVELIST:CVE-2020-14024
HistorySep 22, 2020 - 5:39 p.m.

CVE-2020-14024

2020-09-2217:39:20
mitre
www.cve.org
2
ozeki ng
sms gateway
xss
vulnerabilities
authenticated
stored
reflected
mailbox feature
ozform_groupname
group configuration
addresses
listname
defining address lists
application url
get parameter

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

39.5%

Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFORM_GROUPNAME field in the Group configuration of addresses, (3) listname field in the Defining address lists configuration, or (4) any GET Parameter in the /default URL of the application.

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

39.5%

Related for CVELIST:CVE-2020-14024