Show plain JSON{"id": "CVE-2020-6583", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.3, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 6.1, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 2.7, "exploitabilityScore": 2.8}]}, "published": "2020-01-08T20:15:13.030", "references": [{"url": "https://www.sevenlayers.com/index.php/282-online-invoicing-system-2-6-xss-session-hijack", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.sevenlayers.com/index.php/282-online-invoicing-system-2-6-xss-session-hijack", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-79"}]}], "descriptions": [{"lang": "en", "value": "BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take over the administrator account via the Name field in an Add New Client action."}, {"lang": "es", "value": "BigProf Online Invoicing System (OIS) versiones hasta la versi\u00f3n 2.6, tiene una vulnerabilidad de tipo XSS que puede ser aprovechada para un secuestro de sesi\u00f3n. Un atacante puede explotar la vulnerabilidad de tipo XSS, recuperar la cookie de sesi\u00f3n de inicio de sesi\u00f3n del administrador y tomar el control de la cuenta del administrador por medio del campo Name en una acci\u00f3n Add New Client."}], "lastModified": "2024-11-21T05:36:00.543", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:bigprof:online_invoicing_system:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "397D274D-B3E1-4691-BCC5-022D203B98D8", "versionEndIncluding": "2.6"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}