PT-2020-14829 · Ewon · Ewon Cosy+1
Published
2020-09-18
·
Updated
2021-11-22
·
CVE-2020-16230
CVSS v3.1
2.3
Low
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ewon Flexy and Cosy versions prior to 14.1
Description
The issue allows an attacker with local access and high privileges to inject scripts into the Cross-origin Resource Sharing (CORS) configuration. This could lead to the retrieval of limited confidential information through sniffing, as the software uses wildcards such as (*) under which domains can request resources.
Recommendations
For versions prior to 14.1, update to version 14.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the CORS configuration to minimize the risk of exploitation. Avoid using wildcards in the CORS configuration until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ewon Cosy
Ewon Flexy