HTML Injection Vulnerability in Verint Workforce Optimization
CVE-2020-13480

5.4MEDIUM

Key Information:

Vendor

Verint

Vendor
CVE Published:
22 June 2020

What is CVE-2020-13480?

A vulnerability exists in Verint Workforce Optimization (WFO) 15.2 that allows attackers to exploit the 'send email' feature to inject HTML code. This can lead to various security issues, including phishing attacks or the manipulation of user session data. Proper validation of input data and implementing security measures are crucial to mitigate the risks associated with this vulnerability. Users of the affected version should consider updating their software or applying necessary patches provided by the vendor.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.