CVE-2020-16230
18.09.2020, 19:15
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve limited confidential information through sniffing.Enginsight
| Vendor | Product | Version |
|---|---|---|
| hms-networks | ewon_flexy_firmware | 𝑥 < 14.1 |
| hms-networks | ewon_cosy_firmware | 𝑥 < 14.1 |
𝑥
= Vulnerable software versions