CVE-2020-35309: XSS
Published Jan 21, 2021
·Updated
Bakeshop Online Ordering System in PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML in admin dashboard - "Categories".
Affected Software
1 affected component
Bakeshop Online Ordering System Project Bakeshop Online Ordering System=1.0
Event History
Jan 21, 2021
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35309?
CVE-2020-35309 is considered a high severity vulnerability due to its ability to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2020-35309?
To fix CVE-2020-35309, sanitize user input in the admin dashboard and implement proper output encoding.
3
Which system is affected by CVE-2020-35309?
CVE-2020-35309 affects the Bakeshop Online Ordering System version 1.0.
4
What type of vulnerability is CVE-2020-35309?
CVE-2020-35309 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2020-35309?
Attackers can inject arbitrary web scripts or HTML into the admin dashboard of the Bakeshop Online Ordering System.