CVE-2020-10146 | Microsoft Teams displayName stored cross-site scripting vulnerability
Exp
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This vulnerability was fixed for all Teams users in the online service on or around October 2020.
Conclusion & alert: CVE-2020-10146 is rated High Exploit Risk (66.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.89%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.38% over the last day, indicating growing attacker interest.Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2020-10146
Exploit prediction scoring system (EPSS) score for CVE-2020-10146
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).