VYPR
Low severity3.5NVD Advisory· Published Jan 18, 2023· Updated Jun 17, 2026

CVE-2020-36654

CVE-2020-36654

Description

A vulnerability classified as problematic has been found in GENI Portal. This affects the function no_invocation_id_error of the file portal/www/portal/sliceresource.php. The manipulation of the argument invocation_id/invocation_user leads to cross site scripting. It is possible to initiate the attack remotely. The patch is named 39a96fb4b822bd3497442a96135de498d4a81337. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218475.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Geni/Portal3 versions
    cpe:2.3:a:geni:geni-portal:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:geni:geni-portal:*:*:*:*:*:*:*:*range: <2020-08-27
    • (no CPE)
    • (no CPE)range: n/a

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.