CVE detail
CVE-2020-25715 — CVE-2020-25715
Published 2021-05-28 · Modified 2026-06-17 · Vendor dogtagpki · Product dogtagpki · Source nvd
MEDIUM
severity
CVSS-derived band
0.0114
EPSS probability
exploitation probability, 30d
64.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References