CVE-2020-21101

EUVD-2020-13880
Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could let a remote malicious user execute arbitrary code.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
screenlyscreenly
0.9
screenlyscreenly
0.9.1
screenlyscreenly
0.10
screenlyscreenly
0.11
screenlyscreenly
0.12
screenlyscreenly
0.12.1
screenlyscreenly
0.13
screenlyscreenly
0.14
screenlyscreenly
0.15
screenlyscreenly
0.15.1
screenlyscreenly
0.16
screenlyscreenly
0.17
screenlyscreenly
0.18
screenlyscreenly
0.18.1
screenlyscreenly
0.18.2
𝑥
= Vulnerable software versions