CVE-2020-15914
Summary
| CVE | CVE-2020-15914 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-02 21:15:00 UTC |
| Updated | 2020-11-12 18:44:00 UTC |
| Description | A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ea | Origin Client | All | All | All | All |
| Application | Ea | Origin Client | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security-Advisories/CVE 2020-15914 at master · Monairy/Security-Advisories · GitHub | MISC | github.com | Third Party Advisory |
| EASEC-2020-003 - Cross Site Scripting Vulnerability in Origin Client | MISC | www.ea.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.