CVE-2020-19586
CRITICALYellowfinbi Business Intelligence - XSS
Title source: ruleDescription
Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
Exploits (1)
Scores
CVSS v3
9.0
EPSS
0.0145
EPSS Percentile
80.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-79
Status
published
Products (1)
yellowfinbi/business_intelligence
7.3
Published
Sep 14, 2022
Tracked Since
Feb 18, 2026