Vulnerabilities (CVE)

Filtered by vendor Elastic Subscribe
Filtered by product Elastic App Search
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-7011 1 Elastic 1 Elastic App Search 2020-06-05 4.3 MEDIUM 6.1 MEDIUM
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim�s web browser.