CVE-2020-7303

CVSS v3 Score
4.1
Medium
CVSS v2 Score
2.3
Low

Vulnerability Description

Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label.

CVSS:4.1(Medium)

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, ...

CWE-792019
CVSS:4.1(Medium)

sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that ...

CWE-792021
CVSS:4.1(Medium)

Cross-site scripting in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable information disclosure via local access.

CWE-792022
CVSS:4.1(Medium)

Cross-site Scripting (XSS) - Stored in GitHub repository mkucej/i-librarian-free prior to 5.10.4.

CWE-792023
CVSS:4.1(Medium)

Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability

CWE-792023
CVSS:4.1(Medium)

SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently e...

CWE-792024