CVE-2020-13168

SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
sysaidsysaid_on-premises
5.0
sysaidsysaid_on-premises
5.5.06
sysaidsysaid_on-premises
5.6
sysaidsysaid_on-premises
6.0.9
sysaidsysaid_on-premises
6.5
sysaidsysaid_on-premises
7.0
sysaidsysaid_on-premises
7.5
sysaidsysaid_on-premises
8.0
sysaidsysaid_on-premises
8.1
sysaidsysaid_on-premises
8.5
sysaidsysaid_on-premises
9.0.10
sysaidsysaid_on-premises
9.0.30
sysaidsysaid_on-premises
9.0.40
sysaidsysaid_on-premises
9.0.52
sysaidsysaid_on-premises
9.0.53
sysaidsysaid_on-premises
9.1.0
sysaidsysaid_on-premises
14.1
sysaidsysaid_on-premises
14.2
sysaidsysaid_on-premises
14.3
sysaidsysaid_on-premises
14.4.00
sysaidsysaid_on-premises
14.4.1
sysaidsysaid_on-premises
14.4.2
sysaidsysaid_on-premises
14.4.3
sysaidsysaid_on-premises
15.1.20
sysaidsysaid_on-premises
15.1.30
sysaidsysaid_on-premises
15.1.50
sysaidsysaid_on-premises
15.1.70
sysaidsysaid_on-premises
15.2.03
sysaidsysaid_on-premises
15.2.04
sysaidsysaid_on-premises
15.2.05
sysaidsysaid_on-premises
16.3.16
sysaidsysaid_on-premises
16.3.17
sysaidsysaid_on-premises
17.2.03
sysaidsysaid_on-premises
17.3.57
sysaidsysaid_on-premises
18.1.54
sysaidsysaid_on-premises
19.2
sysaidsysaid_on-premises
19.4
sysaidsysaidsy_on-premises
20.1.11:b26
𝑥
= Vulnerable software versions