CVEs Blog | G5 Cyber Security

CVE-2020-23832 – A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.ph

A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23832

Reference (s):

Exit mobile version