CVE-2020-15869

Executive Summary

CVE‑2020‑15869 exposes Sonatype Nexus Repository Manager OSS/Pro (v≤3.25.0) to cross‑site scripting via crafted input, enabling attackers to inject malicious scripts into the web UI. The flaw can lead to session hijacking, data theft, or defacement. Affected installations lacking the 3.25.1 patch remain vulnerable; no KEV listing yet.


Authoritative CVE Metadata - CVSS Base Score: 5.4 (MEDIUM) - Published: 2020-07-31T20:15:12.580 - Last Modified: 2026-09-22T18:12:03.343

Original Description: Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).

"When one tugs at a single thing in nature, he finds it attached to the rest of the world."

— John Muir
Source: NVD