CVE-2020-19586

CRITICAL

Yellowfin Business Intelligence 7.3 - Stored Cross-Site Scripting via MIAdminStyles.i4 Admin UI

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-19586. PoCs published by Deepak983.

Description

Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.

Exploits (1)

Scores

CVSS v3 9.0
EPSS 0.0117
EPSS Percentile 63.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
yellowfinbi/business_intelligence 7.3
Published Sep 14, 2022
Tracked Since Feb 18, 2026