CVE-2020-5842
MEDIUMCodoforum 4.8.3 - Stored Cross-Site Scripting via User Registration Username Field
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-5842. PoCs published by Prasanth, prasanthc41m.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Codoforum 4.8.3 by injecting malicious JavaScript into the username field during user registration, which triggers when an admin views the user management page.
Description
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page.
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in Codoforum 4.8.3 by injecting malicious JavaScript into the username field during user registration, which triggers when an admin views the user management page.
This repository provides a detailed technical writeup of CVE-2020-5842, a stored XSS vulnerability in Codoforum 4.8.3. It includes step-by-step recreation instructions, affected components, and mitigation strategies.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N