VDB
CVE-2020-9055
CVE-2020-9055
PUBLISHED
CVSS 3.9000000953674316 LOW
Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.
EPSS 0.31% · 54.4th percentile
Risk Scores
CVSS 3.1
3.9000000953674316
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
EPSS Score
0.31%
54.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Versiant | LYNX Customer Service Portal | 3.5.2 |
| versiant | lynx_customer_service_portal | 3.5.2 |
Timeline
- Mar 30, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- VU#962085 third-party-advisory
- https://csp.poha.com/lynx/ url
- https://nvd.nist.gov/vuln/detail/CVE-2020-9055 advisory
- https://csp.poha.com/lynx url
- https://kb.cert.org/vuls/id/962085 url