Medium severity4.8NVD Advisory· Published Jun 8, 2021· Updated Jun 17, 2026
CVE-2020-26517
CVE-2020-26517
Description
A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application configuration (Admin only).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:intland:codebeamer:10.0.0:-:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:intland:codebeamer:10.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.0.0:prerelease4:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.0.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.0.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.0.1:sp1:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.1.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.1.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.1.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:10.1.0:sp4:*:*:*:*:*:*
- cpe:2.3:a:intland:codebeamer:21.04:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 10.x through 10.1.SP4
Patches
Vulnerability mechanics
References
2- www.compass-security.com/fileadmin/Research/Advisories/2021-10_CSNC-2020-012-codebeamer_ALM_XSS.txtnvdExploitThird Party Advisory
- intland.com/codebeamer/application-lifecycle-management/nvdVendor Advisory
News mentions
0No linked articles in our index yet.