CVE Feed

    Dashboard / CVE / CVE-2020-16270

    CVE-2020-16270

    OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject malicious JavaScript payload to victim’s browsers in context of vulnerable applications. Executed code can be used to steal administrator’s cookies, influence HTML content of targeted application and perform phishing-related attacks. Vulnerable application used in more than 3000 organizations in different sectors from retail to industries.

    Published:Oct 16, 2020
    Last Modified:Nov 21, 2024
    EPS:Oct 16, 2020
    EPSS Score:0.2994
    CVSS Score:6.1

    Affected Products

    Vendor
    Olimpoks
    Product
    Olimpok

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High