Логотип exploitDog
bind:CVE-2020-26680
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26680

Количество 2

Количество 2

nvd логотип

CVE-2020-26680

больше 4 лет назад

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-f24c-hgx2-f289

больше 3 лет назад

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26680

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-f24c-hgx2-f289

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу