CVE detail
CVE-2020-13821 — CVE-2020-13821
Published 2020-08-26 · Modified 2026-06-17 · Vendor hivemq · Product broker_control_center · Source nvd
MEDIUM
severity
CVSS-derived band
0.0053
EPSS probability
exploitation probability, 30d
42.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An issue was discovered in HiveMQ Broker Control Center 4.3.2. A crafted clientid parameter in an MQTT packet (sent to the Broker) is reflected in the client section of the management console. The attacker's JavaScript is loaded in a browser, which can lead to theft of the session and cookie of the administrator's account of the Broker.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References