Record summary

CVE-2020-28141 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.

Description

The messaging subsystem in the Online Discussion Forum 1.0 is vulnerable to XSS in the message body. An authenticated user can send messages to arbitrary users on the system that include javascript that will execute when viewing the messages page.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOnline Discussion Forum Site 1.0 - XSS in Messaging SystemExploitDB exploitby j5ohNot analyzed1 file
ExploitDB

PoC details

References

2