CVE-2020-35252
MEDIUMUser Registration & Login System with Admin Panel 1.0 - Cross-Site Scripting via Full Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-35252. PoCs published by Soushikta Chowdhury.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in EgavilanMedia User Registration & Login System with Admin Panel 1.0. The payload is injected via the 'Full Name' field during registration and executes when viewed in the admin panel's 'Manage Users' section.
Description
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in EgavilanMedia User Registration & Login System with Admin Panel 1.0. The payload is injected via the 'Full Name' field during registration and executes when viewed in the admin panel's 'Manage Users' section.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N