CVE-2020-6845

MEDIUM

Topmanage Olk Webstore - XSS

Title source: rule
STIX 2.1

Description

An issue was discovered in TopManage OLK 2020. As there is no ReadOnly on the Session cookie, the user and admin accounts can be taken over in a DOM-Based XSS attack.

Exploits (1)

exploitdb WORKING POC
by Joel Aviad Ossi · textwebappsasp
https://www.exploit-db.com/exploits/47960

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 46.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
topmanage/olk_webstore 2020
Published Feb 18, 2020
Tracked Since Feb 18, 2026