Vulnerabilities (CVE)

Filtered by vendor Safe Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-22789 1 Safe 1 Fme Server 2021-06-17 4.3 MEDIUM 6.1 MEDIUM
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is executed when an administrator accesses the logs.
CVE-2020-22790 1 Safe 1 Fme Server 2021-06-17 3.5 LOW 5.4 MEDIUM
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.