XSS Vulnerability in Inline Attribute Escaping

XSS Vulnerability in Inline Attribute Escaping

CVE-2020-15263 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.

Learn more about our User Device Pen Test.