CVE-2020-36850
BaseFortify
Publication date: 2025-07-25
Last updated on: 2025-07-29
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sitecore | jss_react_sample_application | 11.0.0 |
| sitecore | jss_react_sample_application | 14.0.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2020-36850 is an information disclosure vulnerability in the Sitecore JSS React Sample Application versions 11.0.0 to 14.0.1. It may cause page content intended for one user to be shown to another user, allowing unauthorized access to sensitive information. The vulnerability is remotely exploitable without authentication or user interaction and has a high severity rating. [1]
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized disclosure of sensitive information by showing page content meant for one user to another user. This can compromise confidentiality and potentially expose private or sensitive data to unintended parties. [1]