{"id":"CVE-2020-36654","details":"A vulnerability classified as problematic has been found in GENI Portal. This affects the function no_invocation_id_error of the file portal/www/portal/sliceresource.php. The manipulation of the argument invocation_id/invocation_user leads to cross site scripting. It is possible to initiate the attack remotely. The patch is named 39a96fb4b822bd3497442a96135de498d4a81337. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218475.","modified":"2026-07-08T05:56:27.199273936Z","published":"2023-01-18T08:15:10.073Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"geni:geni-portal","cpes":["cpe:2.3:a:geni:geni-portal:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"2020-08-27"}]}]},"references":[{"type":"ADVISORY","url":"https://vuldb.com/?id.218475"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.218475"},{"type":"FIX","url":"https://github.com/GENI-NSF/geni-portal/commit/39a96fb4b822bd3497442a96135de498d4a81337"},{"type":"FIX","url":"https://github.com/GENI-NSF/geni-portal/pull/1824"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/geni-nsf/geni-portal","events":[{"introduced":"0"},{"fixed":"39a96fb4b822bd3497442a96135de498d4a81337"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v3.26","v3.25","v3.24","v3.23","v3.22","v3.21","v3.20","v2.29.2","v2.29.1","v2.29","v2.28.1","v2.18.1","v2.17.1","v2.16.6","v2.16.4","v2.16.3","v2.5.1","v2.3.1","v2.1","v2.0","v1.9.6","v1.9.5","v1.9.4","v1.9.3","v1.9.2","v1.9.1","v1.9","v1.8.1","v1.8","v1.7.1","v1.7","v1.6.2","v1.6.1","1.6.1","v1.6","v1.5","v1.4","v1.3.1","1.3.1","v1.3","v1.0","v0.4","v0.3","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-36654.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}