CVE-2020-7132
MEDIUMHPE Onboard Administrator - Reflected Cross-Site Scripting
Title source: llmDescription
A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve the vulnerability in HPE Onboard Administrator. * OA 4.95 (Linux and Windows).
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03988en_us
Vendor Advisory x_refsource_misc
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf03988en_us
Scores
CVSS v3
5.4
EPSS
0.0022
EPSS Percentile
45.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
hp/onboard_administrator
4.85
Published
Apr 23, 2020
Tracked Since
Feb 18, 2026