Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-9036. PoCs published by tnpitsecurity. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2020-9036, a reflected XSS vulnerability in Jeedom that can be chained with CSRF token extraction to achieve remote code execution. It includes proof-of-concept URLs and JavaScript payloads demonstrating the exploit chain.
Description
Jeedom through 4.0.38 allows XSS.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2020-9036, a reflected XSS vulnerability in Jeedom that can be chained with CSRF token extraction to achieve remote code execution. It includes proof-of-concept URLs and JavaScript payloads demonstrating the exploit chain.
Nuclei Templates (1)
http.title:"jeedom"
title="jeedom"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N