Vulnerability Description
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Egavilanmedia | Expense Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://nikhilkumar01.medium.com/cve-2020-35395-cd393ac8371cExploitThird Party Advisory
- https://www.exploit-db.com/exploits/49146ExploitThird Party AdvisoryVDB Entry
- https://nikhilkumar01.medium.com/cve-2020-35395-cd393ac8371cExploitThird Party Advisory
- https://www.exploit-db.com/exploits/49146ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-35395?
CVE-2020-35395 is a vulnerability with a CVSS score of 6.1 (MEDIUM). XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
How severe is CVE-2020-35395?
CVE-2020-35395 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35395?
Check the references section above for vendor advisories and patch information. Affected products include: Egavilanmedia Expense Management System.