Vulnerability Description
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alumni Management System Project | Alumni Management System | 1.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/160591/Alumni-Management-System-1.0-Cross-SExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/160591/Alumni-Management-System-1.0-Cross-SExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-28071?
CVE-2020-28071 is a vulnerability with a CVSS score of 4.8 (MEDIUM). SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS p...
How severe is CVE-2020-28071?
CVE-2020-28071 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28071?
Check the references section above for vendor advisories and patch information. Affected products include: Alumni Management System Project Alumni Management System.