Candidate: CVE-2020-27741 PublicDate: 2020-10-28 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27741 http://uncensored.citadel.org/readfwd?go=Citadel%20Security?start_reading_at=4592834 https://www.citadel.org/ Description: Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=973385 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_webcit: upstream_webcit: needs-triage precise/esm_webcit: DNE trusty_webcit: ignored (out of standard support) trusty/esm_webcit: DNE xenial_webcit: ignored (end of standard support, was needs-triage) bionic_webcit: needs-triage focal_webcit: needs-triage groovy_webcit: ignored (reached end-of-life) hirsute_webcit: DNE impish_webcit: DNE jammy_webcit: DNE devel_webcit: DNE