CVE-2020-25071 describes a stored Cross-Site Scripting (XSS) vulnerability in the Nifty Project Management Web Application (version 2020-08-26). An authenticated attacker can inject malicious script via the "Add Task" function, which executes when a user visits the affected Project Home page. This vulnerability is rated Medium (CVSS 5.4), requiring user interaction and low privileges, with potential for limited confidentiality and integrity impact. While the original report claimed reproducibility, subsequent analysis suggests the XSS attributes are now stripped, making current exploitation unlikely. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2020-08-26CPE matchmatch criteria | cpe:2.3:a:niftypm:nifty:2020-08-26:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.