CVE-2020-25864
MEDIUM NUCLEIHashicorp Consul < 1.7.14 - XSS
Title source: ruleDescription
HashiCorp Consul and Consul Enterprise up to version 1.9.4 key-value (KV) raw mode was vulnerable to cross-site scripting. Fixed in 1.9.5, 1.8.10 and 1.7.14.
Nuclei Templates (1)
HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site Scripting
MEDIUMby c-sh0
Shodan:
http.title:"consul by hashicorp" || cpe:"cpe:2.3:a:hashicorp:consul"
FOFA:
title="consul by hashicorp"
Scores
CVSS v3
6.1
EPSS
0.8334
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
hashicorp/consul
< 1.7.14 (2 CPE variants)
hashicorp/consul
1.9.0 - 1.9.5Go
Published
Apr 20, 2021
Tracked Since
Feb 18, 2026