CVE-2020-15870
Executive Summary
CVE-2020-15870 exposes Sonatype Nexus Repository Manager OSS/Pro (versions <3.25.1) to cross‑site scripting via crafted input. Attackers can inject malicious scripts that execute in the victim’s browser when the vulnerable UI renders, potentially leading to session hijacking, data theft, or defacement. The flaw is client‑side and does not require authentication, making it exploitable by unauthenticated users. Affected deployments should upgrade to 3.25.1 or later.
Authoritative CVE Metadata - CVSS Base Score: 6.1 (MEDIUM) - Published: 2020-07-31T20:15:12.673 - Last Modified: 2026-09-22T18:10:02.617
Original Description: Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
"It is the mark of an educated mind to be able to entertain a thought without accepting it."
— Aristotle