CVE-2020-15870

Executive Summary

CVE-2020-15870 exposes Sonatype Nexus Repository Manager OSS/Pro (versions <3.25.1) to cross‑site scripting via crafted input. Attackers can inject malicious scripts that execute in the victim’s browser when the vulnerable UI renders, potentially leading to session hijacking, data theft, or defacement. The flaw is client‑side and does not require authentication, making it exploitable by unauthenticated users. Affected deployments should upgrade to 3.25.1 or later.


Authoritative CVE Metadata - CVSS Base Score: 6.1 (MEDIUM) - Published: 2020-07-31T20:15:12.673 - Last Modified: 2026-09-22T18:10:02.617

Original Description: Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).

"It is the mark of an educated mind to be able to entertain a thought without accepting it."

— Aristotle
Source: NVD