Medium severity6.1NVD Advisory· Published Apr 7, 2020· Updated Jun 17, 2026
CVE-2020-6171
CVE-2020-6171
Description
A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Affected products
3- cpe:2.3:a:communilink:clink_office:2.0:*:*:*:*:*:*:*
- CLink Office/CLink Officedescription
Patches
Vulnerability mechanics
References
1- www.deepcode.ca/index.php/2020/04/07/cve-2020-xss-in-clink-office-v2/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.