PT-2020-14829 · Ewon · Ewon Cosy+1

Published

2020-09-18

·

Updated

2021-11-22

·

CVE-2020-16230

CVSS v3.1

2.3

Low

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ewon Flexy and Cosy versions prior to 14.1
Description The issue allows an attacker with local access and high privileges to inject scripts into the Cross-origin Resource Sharing (CORS) configuration. This could lead to the retrieval of limited confidential information through sniffing, as the software uses wildcards such as (*) under which domains can request resources.
Recommendations For versions prior to 14.1, update to version 14.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the CORS configuration to minimize the risk of exploitation. Avoid using wildcards in the CORS configuration until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-16230

Affected Products

Ewon Cosy
Ewon Flexy