CVE-2020-25761
MEDIUMProjectworlds Visitor Management System 1.0 - Cross-Site Scripting via myform.php Request Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-25761. PoCs published by Rahul Ramkumar.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Visitor Management System in PHP 1.0 by injecting a malicious script into the 'comment' parameter, which is then retrieved and displayed to other users.
Description
Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Visitor Management System in PHP 1.0 by injecting a malicious script into the 'comment' parameter, which is then retrieved and displayed to other users.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N