From df034a7f69609cad21fd1e81ff4a1138acaf94be Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Tue, 19 Jan 2021 07:26:46 +0100 Subject: Add CVE-2020-16255/owncloud --- data/CVE/list | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/CVE/list b/data/CVE/list index 21255e13e3..90dadb7fd3 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -47269,7 +47269,7 @@ CVE-2020-16257 (Winston 1.5.4 devices are vulnerable to command injection via th CVE-2020-16256 (The API on Winston 1.5.4 devices is vulnerable to CSRF. ...) NOT-FOR-US: Winston devices CVE-2020-16255 (ownCloud (Core) before 10.5 allows XSS in login page 'forgot password. ...) - TODO: check + - owncloud CVE-2020-16254 (The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets ...) NOT-FOR-US: Chartkick gem CVE-2020-16253 (The PgHero gem through 2.6.0 for Ruby allows CSRF. ...) -- cgit v1.2.3