Beveiligingsadvies

CVE-2020-29455

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-12-11 19:50:44
Laatst bijgewerkt 2024-08-04 16:55:10
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).