Vulnerability Details CVE-2020-28364
A stored cross-site scripting (XSS) vulnerability affects the Web UI in Locust before 1.3.2, if the installation violates the usage expectations by exposing this UI to outside users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.4%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-28364
-
cpe:2.3:a:locust:locust:0.10.0
-
cpe:2.3:a:locust:locust:0.12.1
-
cpe:2.3:a:locust:locust:0.12.2
-
cpe:2.3:a:locust:locust:0.13.0
-
cpe:2.3:a:locust:locust:0.13.1
-
cpe:2.3:a:locust:locust:0.13.2
-
cpe:2.3:a:locust:locust:0.13.3
-
cpe:2.3:a:locust:locust:0.13.4
-
cpe:2.3:a:locust:locust:0.13.5
-
cpe:2.3:a:locust:locust:0.14.0
-
cpe:2.3:a:locust:locust:0.14.6
-
cpe:2.3:a:locust:locust:0.4
-
cpe:2.3:a:locust:locust:0.5
-
cpe:2.3:a:locust:locust:0.5.1
-
cpe:2.3:a:locust:locust:0.6
-
cpe:2.3:a:locust:locust:0.7
-
cpe:2.3:a:locust:locust:0.7.1
-
cpe:2.3:a:locust:locust:0.7.2
-
cpe:2.3:a:locust:locust:0.7.3
-
cpe:2.3:a:locust:locust:0.7.4
-
cpe:2.3:a:locust:locust:0.7.5
-
cpe:2.3:a:locust:locust:0.8
-
cpe:2.3:a:locust:locust:0.8.1
-
cpe:2.3:a:locust:locust:0.9.0
-
cpe:2.3:a:locust:locust:1.0
-
cpe:2.3:a:locust:locust:1.0.1
-
cpe:2.3:a:locust:locust:1.0.2
-
cpe:2.3:a:locust:locust:1.0.3
-
cpe:2.3:a:locust:locust:1.1
-
cpe:2.3:a:locust:locust:1.1.1
-
cpe:2.3:a:locust:locust:1.2
-
cpe:2.3:a:locust:locust:1.2.1
-
cpe:2.3:a:locust:locust:1.2.2
-
cpe:2.3:a:locust:locust:1.2.3
-
cpe:2.3:a:locust:locust:1.3.0
-
cpe:2.3:a:locust:locust:1.3.1