- Description
- Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.
- Source
- vultures@jpcert.or.jp
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
- nvd@nist.gov
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:desknets:neo:*:*:*:*:small_license:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A54B60E3-C78B-43D6-9D02-239136DDEED0",
"versionEndIncluding": "5.5"
},
{
"criteria": "cpe:2.3:a:desknets:neo:5.5:r1.5:*:*:small_license:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0FBD8C0D-DEE7-43B8-A590-50AE14F5A3EC"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:desknets:neo:*:*:*:*:enterprise_license:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D64D495-6EF5-4541-99F6-A7659B2B8CF6",
"versionEndIncluding": "5.5"
},
{
"criteria": "cpe:2.3:a:desknets:neo:5.5:r1.5:*:*:enterprise_license:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57A0D251-8D6F-4174-8DF4-A2AD7A349156"
}
],
"operator": "OR"
}
]
}
]