Developer Tools & Libraries

Cross-Site Scripting (XSS)

massCode Code execution

massCode Code execution This vulnerability allows an attacker perfrom code execution on massCode editor

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS29
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-8548
VENDORS
massCode
PUBLIC EXPLOIT
PoC public
CWE
CWE-79
PRODUCT
massCode (Windows/Mac/Linux)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

massCode Code execution

This vulnerability allows an attacker perfrom code execution on massCode editor

Vulnerability details

Vulnerability details

CVE-2020-8548
CWE-79
Medium | 6.1

massCode Code execution This vulnerability allows an attacker perfrom code execution on massCode editor

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2020-02-01 reported to the vendor

2020-02-04 fixed released by the vendor

Credits

Nikhil Mittal