CVE-2020-26505
Last modified
CVE-2020-26505 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker to perform unauthorized actions in the application on behalf of legitimate users or spread malware via the application. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
A Stored Cross-Site Scripting (XSS) vulnerability in the “Marmind” web application with version 4.1.141.0 allows an attacker to inject code that will later be executed by legitimate users when they open the assets containing the JavaScript code. This would allow an attacker to perform unauthorized actions in the application on behalf of legitimate users or spread malware via the application. By using the “Assets Upload” function, an attacker can abuse the upload function to upload a malicious PDF file containing a stored XSS.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Marmind | Marmind | 4.1.141.0 |
References
- https://www.marmind.com/en/Vendor Advisory
- https://www2.deloitte.com/de/de/pages/risk/articles/marmind-xss.html?nc=1Exploit, Third Party Advisory
- https://www.marmind.com/en/Vendor Advisory
- https://www2.deloitte.com/de/de/pages/risk/articles/marmind-xss.html?nc=1Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-26505?
How severe is CVE-2020-26505?
How do I fix CVE-2020-26505?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-2645Vulnerability in the Enterprise Manager Base Platform produc…6
- CVE-2020-2646Vulnerability in the Enterprise Manager Base Platform produc…5.4
- CVE-2020-2647Vulnerability in the Oracle Solaris product of Oracle System…5
- CVE-2020-2648Vulnerability in the Oracle Retail Customer Management and S…6.2
- CVE-2020-2649Vulnerability in the Oracle Retail Customer Management and S…3.3
- CVE-2020-2650Vulnerability in the Oracle Retail Customer Management and S…6.5
- CVE-2020-26506An Authorization Bypass vulnerability in the Marmind web app…4.3
- CVE-2020-26507A CSV Injection (also known as Formula Injection) vulnerabil…7.8
- CVE-2020-26508The WebTools component on Canon Oce ColorWave 3500 5.1.1.0 d…9.8
- CVE-2020-26509Airleader Master and Easy <= 6.21 devices have default crede…7.5
- CVE-2020-2651Vulnerability in the Oracle CRM Technical Foundation product…8.2
- CVE-2020-26510Airleader Master <= 6.21 devices have default credentials th…9.8
Are you affected by CVE-2020-26505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
