CVE-2020-6171

MEDIUM NUCLEI

CLink Office 2.0 - Cross-Site Scripting via Lang Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-6171 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

Nuclei Templates (1)

CLink Office 2.0 - Cross-Site Scripting
MEDIUMby pikpikcu

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0480
EPSS Percentile 90.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
communilink/clink_office 2.0
Published Apr 07, 2020
Tracked Since Feb 18, 2026