CVE-2020-16270
OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
OLIMPOKS under 3.3.39 allows Auth/Admin ErrorMessage XSS. Remote Attacker can use discovered vulnerability to inject malicious JavaScript payload to victim’s browsers in context of vulnerable applications. Executed code can be used to steal administrator’s cookies, influence HTML content of targeted application and perform phishing-related attacks. Vulnerable application used in more than 3000 organizations in different sectors from retail to industries.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 13.11% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- olimpoks/olimpok
- Source
- cve@mitre.org
References
- https://bdu.fstec.ru/vul/2020-04623Third Party Advisory
- https://github.com/Security-AVS/CVE-2020-16270Third Party Advisory
- https://olimpoks.ru/oks/forum/olimpoks5.phpProduct, Vendor Advisory
- https://bdu.fstec.ru/vul/2020-04623Third Party Advisory
- https://github.com/Security-AVS/CVE-2020-16270Third Party Advisory
- https://olimpoks.ru/oks/forum/olimpoks5.phpProduct, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.