ZeroHour

CVE-2020-23832

PoC
CVSS 3.1
6.1 medium
EPSS
2%p81
Published
()
Modified
Description

A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

Vendors
car rental management system project
Products
car rental management system
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.