// For flags

CVE-2020-29231

 

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.

EGavilanMedia User Registration and Login System With Admin Panel versión 1.0, está afectado por una vulnerabilidad de tipo cross-site scripting (XSS) en la Admin Profile Page. Esta vulnerabilidad puede resultar en que el atacante inyecte una carga útil de tipo XSS en el Admin Full Name y cada vez que el administrador visita la página del Perfil desde el panel de administración, se desencadena el ataque de tipo XSS.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-11-27 CVE Reserved
  • 2020-12-30 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Egavilanmedia
Search vendor "Egavilanmedia"
User Registration And Login System With Admin Panel
Search vendor "Egavilanmedia" for product "User Registration And Login System With Admin Panel"
1.0
Search vendor "Egavilanmedia" for product "User Registration And Login System With Admin Panel" and version "1.0"
-
Affected