CVE detail
CVE-2020-25470 — CVE-2020-25470
Published 2020-10-26 · Modified 2026-06-17 · Vendor antsword_project · Product antsword · Source nvd
MEDIUM
severity
CVSS-derived band
0.0133
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References