CVE-2020-29215: XSS
Published Jun 15, 2021
·Updated
A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.
Affected Software
2 affected components
Razormist Employee Management System=1.0
Employee Management System Project Employee Management System=1.0
Event History
Jun 15, 2021
CVE Published
via MITRE·07:57 PM
Data Sourced
via MITRE·07:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-29215?
The severity of CVE-2020-29215 is considered to be medium due to its potential impact on user data and application integrity.
2
How do I fix CVE-2020-29215?
To fix CVE-2020-29215, sanitize user inputs on the affected addemp.php page to prevent Cross Site Scripting attacks.
3
What systems are affected by CVE-2020-29215?
CVE-2020-29215 affects the Employee Management System version 1.0 by both SourceCodester and Razormist.
4
What type of vulnerability is CVE-2020-29215?
CVE-2020-29215 is classified as a Cross Site Scripting (XSS) vulnerability.
5
Can CVE-2020-29215 lead to unauthorized access?
Yes, CVE-2020-29215 could potentially allow attackers to execute scripts in the context of an admin account, leading to unauthorized actions.