CVE Published: 18/09/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: icscert |
Vendor: n/a |
Product: HMS Networks Ewon Flexy and Cosy Status : PUBLISHED
CVE-2020-16230 Description
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.