CVE Identifier: CVE-2020-13480 Vulnerable Software: Verint Workforce Optimization (WFO) Vulnerability Type: HTML Injection Affected Version: 15.2 Vendor Homepage: https://www.verint.com CVE Author: Tejas Nitin Pingulkar Exploit Availability: POC Available Description: The Verint WFO application sends and receives emails but fails to sanitize user input, leading to an HTML injection vulnerability. Exploit Steps: 1. Open send email function 2. Write your payload inside the body POC: Not shown in the screenshot Timeline: - Initial Email Sent: 21 May 2020 — No response - Followup 2: 25 May 2020 — No response - Followup 3: 26 May 2020 — No response - CVE Generated: 26 May 2020 - Followup 4: 08 June 2020 — No response - Published: 09 June 2020