CVE-2020-12882 describes a Cross-Site Scripting (XSS) vulnerability in Submitty versions up to 20.04.01, allowing an authenticated user (e.g., a Student) to inject malicious scripts via SVG file uploads, impacting other users like Teaching Fellows. With a CVSS score of 5.4 (Medium), this vulnerability requires user interaction and low privileges but can lead to partial confidentiality and integrity compromise. While not listed on CISA's KEV catalog, an exploit is publicly available on ExploitDB, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20.04.01CPE matchmatch criteria | cpe:2.3:a:rcos:submitty:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.