Medium severity6.1NVD Advisory· Published Apr 2, 2020· Updated Jun 17, 2026
CVE-2020-11499
CVE-2020-11499
Description
Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:firmware_analysis_and_comparison_tool_project:firmware_analysis_and_comparison_tool:3.0:*:*:*:*:*:*:*
- Firmware Analysis and Comparison Tool (FACT)/Firmware Analysis and Comparison Tool (FACT)description
Patches
Vulnerability mechanics
References
2- github.com/fkie-cad/FACT_core/issues/375nvdExploitPatchThird Party Advisory
- github.com/fkie-cad/FACT_core/pull/376nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.