// For flags

CVE-2020-15914

 

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window.

Se presenta una vulnerabilidad de tipo cross-site scripting (XSS) en Origin Client para Mac y PC versión 10.5.86 que podría permitir a un atacante remoto ejecutar JavaScript arbitrario en Origin Client de un usuario objetivo. Un atacante podría usar esta vulnerabilidad para acceder a datos confidenciales relacionados con la cuenta de Origin del usuario objetivo, o para controlar o monitorear la ventana de chat de texto de Origin

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-07-23 CVE Reserved
  • 2020-10-30 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ea
Search vendor "Ea"
Origin Client
Search vendor "Ea" for product "Origin Client"
<= 10.5.86
Search vendor "Ea" for product "Origin Client" and version " <= 10.5.86"
mac_os
Affected
Ea
Search vendor "Ea"
Origin Client
Search vendor "Ea" for product "Origin Client"
<= 10.5.86
Search vendor "Ea" for product "Origin Client" and version " <= 10.5.86"
windows
Affected