1 results (0.001 seconds)

CVSS: 5.4EPSS: 0%CPEs: 2EXPL: 0

A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window. Se presenta una vulnerabilidad de tipo cross-site scripting (XSS) en Origin Client para Mac y PC versión 10.5.86 que podría permitir a un atacante remoto ejecutar JavaScript arbitrario en Origin Client de un usuario objetivo. Un atacante podría usar esta vulnerabilidad para acceder a datos confidenciales relacionados con la cuenta de Origin del usuario objetivo, o para controlar o monitorear la ventana de chat de texto de Origin • https://github.com/Monairy/Security-Advisories/blob/master/CVE%202020-15914 https://www.ea.com/security/news/easec-2020-003-cross-site-scripting-vulnerability-in-origin-client • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •