CVE-2020-28129: XSS
Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-28129.
What is the severity of CVE-2020-28129?
The severity of CVE-2020-28129 is medium with a CVSS score of 6.1.
How does the vulnerability affect SourceCodester Gym Management System 1.0?
The vulnerability allows users to inject and store arbitrary JavaScript code in index.php?page=packages via the 'Package Name' and 'Description' fields.
How can I exploit CVE-2020-28129?
We do not provide information on how to exploit vulnerabilities. It is recommended to follow responsible disclosure guidelines and report the vulnerability to the vendor.
Is there a fix available for CVE-2020-28129?
It is recommended to update to a patched version of SourceCodester Gym Management System that addresses the XSS vulnerability.