CVE-2020-35396

EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.
References
Link Resource
http://egavilanmedia.com/ Vendor Advisory
https://nikhilkumar01.medium.com/cve-2020-35396-f4b5675fb168 Exploit Third Party Advisory
https://www.exploit-db.com/exploits/49227 Exploit Third Party Advisory VDB Entry
http://egavilanmedia.com/ Vendor Advisory
https://nikhilkumar01.medium.com/cve-2020-35396-f4b5675fb168 Exploit Third Party Advisory
https://www.exploit-db.com/exploits/49227 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:egavilanmedia:barcodes_generator:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:27

Type Values Removed Values Added
References () http://egavilanmedia.com/ - Vendor Advisory () http://egavilanmedia.com/ - Vendor Advisory
References () https://nikhilkumar01.medium.com/cve-2020-35396-f4b5675fb168 - Exploit, Third Party Advisory () https://nikhilkumar01.medium.com/cve-2020-35396-f4b5675fb168 - Exploit, Third Party Advisory
References () https://www.exploit-db.com/exploits/49227 - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/49227 - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2020-12-15 16:15

Updated : 2024-11-21 05:27


NVD link : CVE-2020-35396

Mitre link : CVE-2020-35396

CVE.ORG link : CVE-2020-35396


JSON object : View

Products Affected

egavilanmedia

  • barcodes_generator
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')