Medium severity6.1NVD Advisory· Published Feb 16, 2020· Updated Jun 17, 2026
CVE-2020-9012
CVE-2020-9012
Description
A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.
Affected products
3- cpe:2.3:a:gluu:gluu_server:4.0:*:*:*:*:*:*:*
- Gluu/Identity Configurationdescription
- Range: = 4.0
Patches
Vulnerability mechanics
References
1- support.gluu.org/other/7992/reflected-cross-site-scripting-on-import-people/nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.