First published: Tue Dec 15 2020(Updated: )
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Expense Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35395 is a Cross-Site Scripting (XSS) vulnerability in the Add Expense Component of EGavilan Media Expense Management System 1.0.
An attacker can exploit CVE-2020-35395 by injecting malicious JavaScript code into the 'description' field of the Add Expense Component.
CVE-2020-35395 has a severity level of medium with a CVSSv3 score of 6.1.
The affected software is EGavilan Media Expense Management System 1.0.
To fix CVE-2020-35395, it is recommended to sanitize and validate user inputs to prevent the injection of malicious JavaScript code.