CVE-2020-23450: Spiceworks

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.

Affected products

  • Spiceworks Spiceworks: up to and including 7.5.00107

Published 2020-09-01. Last modified 2026-07-09.