Lucene search

K
cvelistMitreCVELIST:CVE-2020-25761
HistorySep 29, 2020 - 7:06 p.m.

CVE-2020-25761

2020-09-2919:06:00
mitre
www.cve.org
4
projectworlds visitor management system
php
xss
input validation
javascript payloads
stealing cookies
sensitive information

EPSS

0.008

Percentile

81.8%

Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.

EPSS

0.008

Percentile

81.8%

Related for CVELIST:CVE-2020-25761