Lucene search

K
osvGoogleOSV:CVE-2020-21087
HistoryApr 14, 2021 - 2:15 p.m.

CVE-2020-21087

2021-04-1414:15:13
Google
osv.dev
2
cve-2020-21087
cross site scripting
x2engine x2crm
remote attackers
arbitrary code
web script
html
rename a module

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

48.1%

Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web script or HTML via the β€œNew Name” field of the β€œRename a Module” tool.

AI Score

6.5

Confidence

High

EPSS

0.001

Percentile

48.1%

Related for OSV:CVE-2020-21087