CVE-2020-37014

MEDIUM

Tryton 5.4 - XSS

Title source: llm
STIX 2.1

Description

Tryton 5.4 contains a persistent cross-site scripting vulnerability in the user profile name input that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability by inserting script payloads in the name field, which execute in the frontend and backend user interfaces.

Exploits (1)

exploitdb WORKING POC
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/48466

Scores

CVSS v3 6.4
EPSS 0.0007
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Published Jan 30, 2026
Tracked Since Feb 18, 2026