imPC@ndo IT

Tracker / CVE-2020-5901

CVE-2020-5901

Critical 9.6

In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.

Affected products and versions

f5 nginx_controller · 3.3.0 → 3.4.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References