packetstormsecurity.com
http://packetstormsecurity.com/files/160128/PESCMS-TEAM-2.3.2-Cross-Site-Scripting.html CVE-2020-28092
MEDIUM
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
Record summary
CVE-2020-28092 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.
Description
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&status=0&id=,?g=Team&m=Task&a=my&status=1&id=,?g=Team&m=Task&a=my&status=10&id=
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPESCMS TEAM 2.3.2 - Multiple Reflected XSSExploitDB exploitby icekamNot analyzed1 file
References
3github.com
https://github.com/lazyphp/PESCMS-TEAM/issues/6 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28092