CVE-2020-35395

MEDIUM

Egavilanmedia Expense Management System - XSS

Title source: rule
STIX 2.1

Description

XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field

Exploits (1)

exploitdb WORKING POC
by Nikhil Kumar · textwebappsmultiple
https://www.exploit-db.com/exploits/49146

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 46.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
egavilanmedia/expense_management_system 1.0
Published Dec 15, 2020
Tracked Since Feb 18, 2026