CVE-2020-16278: Carson-Saint Saint Security Suite
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link.
Affected products
- Carson-Saint Saint Security Suite: from 8.0, up to and including 9.8.20
Published 2020-08-10. Last modified 2026-06-17.