Unrated severityNVD Advisory· Published Jan 8, 2020· Updated Aug 4, 2024
CVE-2020-6583
CVE-2020-6583
Description
BigProf Online Invoicing System (OIS) through 2.6 has XSS that can be leveraged for session hijacking. An attacker can exploit the XSS vulnerability, retrieve the session cookie from the administrator login, and take over the administrator account via the Name field in an Add New Client action.
Affected products
2- BigProf/Online Invoicing Systemdescription
- Range: <=2.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.sevenlayers.com/index.php/282-online-invoicing-system-2-6-xss-session-hijackmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.