CVE-2020-9299

MEDIUM

Netflix Dispatch < 20201106 - Authenticated Cross-Site Scripting via Incident Priority and Type Parameters

Title source: llm
STIX 2.1

Description

There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.

References (2)

Core 2

Scores

CVSS v3 5.4
EPSS 0.0056
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
netflix/dispatch < 20201106
Published Nov 09, 2020
Tracked Since Feb 18, 2026