CVE-2020-13959 is a cross-site scripting (XSS) vulnerability in Apache Velocity Tools prior to version 3.1, where the default error page for VelocityView reflects user-supplied input. This allows an attacker to inject and execute arbitrary JavaScript by manipulating the URL, affecting Apache Velocity Tools and Debian Linux distributions. Rated 6.1 MEDIUM, the vulnerability requires user interaction (UI:R) but can be exploited remotely (AV:N) with low complexity (AC:L), potentially leading to session hijacking or phishing. There is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), though it has received some community discussion and media coverage, including a report on its impact on government websites.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1CPE matchmatch criteria | cpe:2.3:a:apache:velocity_tools:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.