{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-22T12:53:30.795","vulnerabilities":[{"cve":{"id":"CVE-2020-9447","sourceIdentifier":"cve@mitre.org","published":"2020-02-28T16:15:11.087","lastModified":"2026-06-17T03:27:57.967","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attackers to steal data, change the appearance of a website, and perform other malicious activities like phishing or drive-by hacking."},{"lang":"es","value":"Hay una vulnerabilidad XSS (cross-site scripting) en GwtUpload 1.0.3 en la funcionalidad de carga de archivos. Alguien puede cargar un archivo con un nombre de archivo malicioso, que contiene código JavaScript, lo que daría como resultado XSS. Las secuencias de comandos entre sitios permiten a los atacantes robar datos, cambiar la apariencia de un sitio web y realizar otras actividades maliciosas como el phishing o el pirateo de dispositivos."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gwtupload_project:gwtupload:1.0.3:*:*:*:*:*:*:*","matchCriteriaId":"83DF83B6-87E9-4C19-8616-59B0CE2A0364"}]}]}],"references":[{"url":"https://github.com/manolo/gwtupload/issues/32","source":"cve@mitre.org","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://www.coresecurity.com/advisories/gwtupload-xss-file-upload-functionality","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/manolo/gwtupload/issues/32","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking","Third Party Advisory"]},{"url":"https://www.coresecurity.com/advisories/gwtupload-xss-file-upload-functionality","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}