ZeroHour

CVE-2020-35395

PoC ×2
CVSS 3.1
6.1 medium
EPSS
<1%p56
Published
()
Modified
Description

XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field

Vendors
egavilanmedia
Products
expense management system
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.