ZeroHour

CVE-2020-6845

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p57
Published
()
Modified
Description

An issue was discovered in TopManage OLK 2020. As there is no ReadOnly on the Session cookie, the user and admin accounts can be taken over in a DOM-Based XSS attack.

Vendors
topmanage
Products
olk webstore
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.