CVE-2020-26517
08.06.2021, 13:15
A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application configuration (Admin only).
Vendor | Product | Version |
---|---|---|
intland | codebeamer | 10.0.0 |
intland | codebeamer | 10.0.0:prerelease4 |
intland | codebeamer | 10.0.0:rc1 |
intland | codebeamer | 10.0.0:sp1 |
intland | codebeamer | 10.0.0:sp2 |
intland | codebeamer | 10.0.1:sp1 |
intland | codebeamer | 10.1.0 |
intland | codebeamer | 10.1.0:sp1 |
intland | codebeamer | 10.1.0:sp2 |
intland | codebeamer | 10.1.0:sp3 |
intland | codebeamer | 10.1.0:sp4 |
intland | codebeamer | 21.04 |
𝑥
= Vulnerable software versions
References