ID

VAR-202009-1704


TITLE

XSS vulnerability exists in IF cloud technology website construction display system

Trust: 0.6

sources: CNVD: CNVD-2020-48550

DESCRIPTION

Fuzhou Yihuyun Technology Co., Ltd. was established on December 17, 2018. The company's business scope includes: application software development; cloud software services; information technology consulting services; technology development, technology transfer, technology consulting, and technical services in the field of digital publishing; other information system integration services; online business consulting; business management consulting services; Design, production, agency, and release of various domestic advertisements; office equipment rental services; Internet of Things technical services; artificial intelligence public data platform; network and information security software development; advertising consulting services, etc. The IF Cloud Technology website construction demonstration system has an XSS vulnerability, which can be exploited by an attacker to obtain user cookie information.

Trust: 0.6

sources: CNVD: CNVD-2020-48550

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-48550

AFFECTED PRODUCTS

vendor:fuzhou yihuyunmodel:exhibition websitescope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-48550

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-48550
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2020-48550
severity: MEDIUM
baseScore: 5.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-48550

PATCH

title:XSS vulnerability exists in IF cloud technology website construction display systemurl:https://www.cnvd.org.cn/patchinfo/show/227799

Trust: 0.6

sources: CNVD: CNVD-2020-48550

EXTERNAL IDS

db:CNVDid:CNVD-2020-48550

Trust: 0.6

sources: CNVD: CNVD-2020-48550

SOURCES

db:CNVDid:CNVD-2020-48550

LAST UPDATE DATE

2022-05-04T09:55:29.352000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-48550date:2020-08-26T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-48550date:2020-09-12T00:00:00