CVE-2020-29230
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.
EGavilanMedia User Registration and Login System With Admin Panel versión 1.0, está afectado por un vulnerabilidad de tipo cross-site scripting (XSS) en la pestaña Manage User de Admin Panel usando el Full Name del usuario. Esta vulnerabilidad puede resultar en que el atacante inyecte una carga útil de tipo XSS en la sección User Registration y cada vez que el administrador visite la sección de administración de usuarios desde el panel de administración, el XSS se desencadena y el atacante puede ser capaz de robar la cookie de acuerdo con la carga útil diseñada.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-11-27 CVE Reserved
- 2020-12-30 CVE Published
- 2023-09-15 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/hemantsolo/CVE-Reference/blob/main/CVE-2020-29230.md | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://egavilanmedia.com | 2021-01-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Egavilanmedia Search vendor "Egavilanmedia" | User Registration And Login System With Admin Panel Search vendor "Egavilanmedia" for product "User Registration And Login System With Admin Panel" | 1.0 Search vendor "Egavilanmedia" for product "User Registration And Login System With Admin Panel" and version "1.0" | - |
Affected
|