Lucene search

K
osvGoogleOSV:CVE-2020-25715
HistoryMay 28, 2021 - 11:15 a.m.

CVE-2020-25715

2021-05-2811:15:07
Google
osv.dev
10
pki-core 10.9.0
xss attack
post request
data integrity

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

37.3%

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.