An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. Two Cross Side Scripting (XSS) vulnerabilities have been found in the Public Web and the Certificate/CRL download servlets.
References
Link | Resource |
---|---|
https://support.primekey.com/news/primekey-announcements | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-04-07 17:15
Updated : 2020-04-08 11:12
NVD link : CVE-2020-11626
Mitre link : CVE-2020-11626
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
primekey
- ejbca