Cross-Site Scripting Vulnerability in EGavilanMedia User Registration and Login System
CVE-2020-29230

6.1MEDIUM

What is CVE-2020-29230?

The EGavilanMedia User Registration and Login System version 1.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability in the Admin Panel's Manage User tab. This issue arises when an attacker is able to inject malicious scripts via the Full Name input in the User Registration section. Each time an administrator accesses the Manage User section, the injected payload executes, potentially allowing the attacker to steal sensitive cookies through crafted scripts.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.