CVE-2020-15864: Quali Cloudshell

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page.

Affected products

  • Quali Cloudshell: version 9.3 only

Published 2021-01-17. Last modified 2026-06-17.