A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16275
Reference (s):
- https://download.saintcorporation.com/products/saint_advisory15.txt