CVE-2020-35416
MEDIUMPHPJabbers Appointment Scheduler 2.3 - Cross-Site Scripting in Admin Login Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-35416. PoCs published by Andrea Intilangelo.
AI-analyzed exploit summary This is a working proof-of-concept for a reflected XSS vulnerability in PHPJabbers Appointment Scheduler 2.3. The exploit demonstrates arbitrary JavaScript execution via the 'date' parameter in a GET request.
Description
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.
Exploits (1)
This is a working proof-of-concept for a reflected XSS vulnerability in PHPJabbers Appointment Scheduler 2.3. The exploit demonstrates arbitrary JavaScript execution via the 'date' parameter in a GET request.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N