First published: Fri Oct 30 2020(Updated: )
A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Electronic Arts Origin | <=10.5.86 | |
Electronic Arts Origin | <=10.5.86 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15914 is classified as a high-severity cross-site scripting (XSS) vulnerability.
To fix CVE-2020-15914, update the Origin Client to version 10.5.87 or later.
CVE-2020-15914 affects the Origin Client for Mac and PC versions 10.5.86 or earlier.
An attacker exploiting CVE-2020-15914 could execute arbitrary JavaScript within a target user's Origin client.
There are currently no known workarounds for CVE-2020-15914 other than updating to the latest version.