685
VMScore

CVE-2019-11354

Published: 19/04/2019 Updated: 18/04/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ea origin 10.5.36

Exploits

# Exploit Title: dotProject 219 - Multiple Sql Injection (Poc) # Exploit Author: Metin Yunus Kandemir (kandemir) # Vendor Homepage: dotprojectnet # Software Link: githubcom/dotproject/dotProject/archive/v219zip # Version: 219 # Category: Webapps # Tested on: Xampp for Windows # Software Description : dotProject is a volunte ...
EA Origin versions prior to 10538 suffer from a remote code execution vulnerability ...
EA Origin versions prior to 10536 suffer from a remote code execution vulnerability via template injection leveraging cross site scripting ...