VYPR
Medium severity6.1NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026

CVE-2020-22789

CVE-2020-22789

Description

Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is executed when an administrator accesses the logs.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Safe/Fme Server4 versions
    cpe:2.3:a:safe:fme_server:2019.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:safe:fme_server:2019.0:*:*:*:*:*:*:*
    • cpe:2.3:a:safe:fme_server:2019.1:*:*:*:*:*:*:*
    • cpe:2.3:a:safe:fme_server:2019.2:beta:*:*:*:*:*:*
    • cpe:2.3:a:safe:fme_server:2020.0:beta:*:*:*:*:*:*
  • FME/Serverdescription
  • Range: 2019.2, 2020.0 Beta

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.