CVE-2020-28957: XSS
Published Oct 22, 2021
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the Customer Add module of Foxlor v0.10.16 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the name, firstname, or username input fields.
Affected Software
4 affected components
composer/froxlor/froxlor=0.10.16
Froxlor Froxlor Debian=0.10.16
Froxlor Froxlor Gentoo=0.10.16
Froxlor Froxlor Ubuntu=0.10.16
Event History
Oct 22, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
May 24, 2022
Advisory Published
via GitHub·07:18 PM
Frequently Asked Questions
1
What is the vulnerability ID of these cross-site scripting (XSS) vulnerabilities?
The vulnerability ID is CVE-2020-28957.
2
What is the affected software version?
The affected software version is Froxlor v0.10.16.
3
What is the severity of this vulnerability?
The severity of the vulnerability is medium, with a CVSS score of 5.4.
4
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by entering a crafted payload into the name, firstname, or username input fields.
5
Is there a fix available for this vulnerability?
Yes, it is recommended to update to a patched version of Froxlor to fix this vulnerability.