Security Advisory

CVE-2020-9388

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-02-03 00:00:00
Last updated 2024-08-04 10:26:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.