Vulnerabilities > Mozilla > Webthings Gateway > 0.10.0

DATE CVE VULNERABILITY TITLE RISK
2020-02-28 CVE-2020-6804 Cross-site Scripting vulnerability in Mozilla Webthings Gateway
A reflected XSS vulnerability exists within the gateway, allowing an attacker to craft a specialized URL which could steal the user's authentication token.
network
mozilla CWE-79
4.3
2020-02-28 CVE-2020-6803 Open Redirect vulnerability in Mozilla Webthings Gateway
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.
network
mozilla CWE-601
5.8