CVE-2020-25715

Source
https://cve.org/CVERecord?id=CVE-2020-25715
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25715.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-25715
Downstream
Published
2021-05-28T11:15:07.640Z
Modified
2026-07-09T00:06:46.484337Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

References

Affected packages

Git / github.com/dogtagpki/pki

Affected ranges

Type
GIT
Repo
https://github.com/dogtagpki/pki
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "10.9.0-NA"
        },
        {
            "last_affected": "10.9.0-NA"
        }
    ],
    "cpe": "cpe:2.3:a:dogtagpki:dogtagpki:10.9.0:-:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

10.*
10.9.0-NA
v10.*
v10.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-25715.json"