CVE-2020-16230
18.09.2020, 19:15
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.Enginsight
Vendor | Product | Version |
---|---|---|
hms-networks | ewon_flexy_firmware | 𝑥 < 14.1 |
hms-networks | ewon_cosy_firmware | 𝑥 < 14.1 |
𝑥
= Vulnerable software versions