BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take over the administrator account via the Name field in an Add New Client action.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-01-08T19:06:46

Updated: 2020-01-08T19:06:46

Reserved: 2020-01-08T00:00:00


Link: CVE-2020-6583

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-01-08T20:15:13.030

Modified: 2020-01-17T15:02:30.477


Link: CVE-2020-6583

JSON object: View

cve-icon Redhat Information

No data.

CWE