CVE-2020-35328: XSS
Published Mar 4, 2021
·Updated
Courier Management System 1.0 - 'First Name' Stored XSS
Affected Software
1 affected component
Courier Management System Project Courier Management System=1.0
Event History
Mar 4, 2021
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35328?
CVE-2020-35328 has a medium severity rating due to its ability to execute stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2020-35328?
To fix CVE-2020-35328, sanitize and validate user input in the 'First Name' field to prevent XSS attacks.
3
What are the potential impacts of CVE-2020-35328?
The potential impacts of CVE-2020-35328 include unauthorized access to user sessions and the execution of malicious scripts in the context of an affected user.
4
Is CVE-2020-35328 easily exploitable?
Yes, CVE-2020-35328 is easily exploitable if an attacker can manipulate input in the 'First Name' field.
5
What versions of Courier Management System are affected by CVE-2020-35328?
CVE-2020-35328 affects Courier Management System version 1.0.