Vulnerability Description
In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vfairs | Vfairs | 3.3 |
Related Weaknesses (CWE)
References
- http://vfairs.comVendor Advisory
- https://www.huntress.com/blog/zero-day-vulnerabilities-in-popular-event-managemeThird Party Advisory
- http://vfairs.comVendor Advisory
- https://www.huntress.com/blog/zero-day-vulnerabilities-in-popular-event-managemeThird Party Advisory
FAQ
What is CVE-2020-26680?
CVE-2020-26680 is a vulnerability with a CVSS score of 5.4 (MEDIUM). In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database...
How severe is CVE-2020-26680?
CVE-2020-26680 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26680?
Check the references section above for vendor advisories and patch information. Affected products include: Vfairs Vfairs.