CVE-2020-35272
MEDIUMEmployee Performance Evaluation System 1.0 - Stored Cross-Site Scripting in Admin Portal Task and Description Fields
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-35272. PoCs published by Ritesh Gohil.
AI-analyzed exploit summary This exploit demonstrates a persistent Cross-Site Scripting (XSS) vulnerability in the Employee Performance Evaluation System 1.0. The payload is injected into the 'Task and Description' fields, triggering when saved and viewed.
Description
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields.
Exploits (1)
This exploit demonstrates a persistent Cross-Site Scripting (XSS) vulnerability in the Employee Performance Evaluation System 1.0. The payload is injected into the 'Task and Description' fields, triggering when saved and viewed.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N