CVE-2020-35272

MEDIUM

Employee Performance Evaluation System 1.0 - Stored Cross-Site Scripting in Admin Portal Task and Description Fields

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-35272. PoCs published by Ritesh Gohil.

AI-analyzed exploit summary This exploit demonstrates a persistent Cross-Site Scripting (XSS) vulnerability in the Employee Performance Evaluation System 1.0. The payload is injected into the 'Task and Description' fields, triggering when saved and viewed.

Description

Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields.

Exploits (1)

exploitdb WORKING POC
by Ritesh Gohil · textwebappsphp
https://www.exploit-db.com/exploits/49215

This exploit demonstrates a persistent Cross-Site Scripting (XSS) vulnerability in the Employee Performance Evaluation System 1.0. The payload is injected into the 'Task and Description' fields, triggering when saved and viewed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Employee Performance Evaluation System 1.0
Auth required
Prerequisites: Admin credentials · Access to the 'Task' feature
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49215

Scores

CVSS v3 4.8
EPSS 0.0059
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
employee_performance_evaluation_system_project/employee_performance_evaluation_system 1.0
Published Jan 20, 2021
Tracked Since Feb 18, 2026