Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20982
Reference (s):
- https://github.com/shadoweb/wdja/issues/1

