Record summary

CVE-2020-19283 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMJeesns 1.4.2 - Cross-Site ScriptingCVSS 6.1

Jeesns 1.4.2 is vulnerable to reflected cross-site scripting in the /newVersion component and allows attackers to execute arbitrary web scripts or HTML.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in a victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade Jeesns to the latest version or apply the vendor-provided patch to fix the XSS vulnerability.

WeaknessesCWE-79
Authorspikpikcu
Template tagscvecve2020jeesnsxssvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:jeesns:jeesns:1.4.2:*:*:*:*:*:*:*
FOFA: title="jeesns"

Source: ProjectDiscovery

References

3