CVE-2020-5223 - CVE House
Back to Database
Status published Medium CVE-2020-5223

Persistent XSS vulnerability in filename of attached file in PrivateBin

Vulnerability Description

In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain conditions, a user provided attachment file name can inject HTML leading to a persistent Cross-site scripting (XSS) vulnerability. The vulnerability has been fixed in PrivateBin v1.3.2 & v1.2.2. Admins are urged to upgrade to these versions to protect the affected users.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5223

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

PrivateBin
Vulnerable Versions:
>= 1.2.0, < 1.2.2, >= 1.3.0, < 1.3.2

Timeline

Official Publish: January 23rd, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N

Weaknesses (CWE)