CVE Database
/

CVE-2020-7011

Back to search

CVE-2020-7011

Published: Jun 3, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim�s web browser.

VendorProductVersions

Elastic

Elastic App Search

affected
before 7.7.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now