CVE-2020-35396: XSS
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of EGavilan Barcodes generator 1.0?
The vulnerability ID of EGavilan Barcodes generator 1.0 is CVE-2020-35396.
What is the severity of CVE-2020-35396?
The severity of CVE-2020-35396 is medium.
How does CVE-2020-35396 affect EGavilan Barcodes generator 1.0?
CVE-2020-35396 affects EGavilan Barcodes generator 1.0 by allowing Cross Site Scripting (XSS) attacks via the index.php file.
How can an attacker exploit CVE-2020-35396?
An attacker can exploit CVE-2020-35396 by injecting XSS payloads in the web application, which will be executed when a user visits the website.
Are there any known exploits for CVE-2020-35396?
Yes, there are known exploits for CVE-2020-35396. You can find more information about them on the following links: [http://egavilanmedia.com/](http://egavilanmedia.com/), [https://nikhilkumar01.medium.com/cve-2020-35396-f4b5675fb168](https://nikhilkumar01.medium.com/cve-2020-35396-f4b5675fb168), [https://www.exploit-db.com/exploits/49227](https://www.exploit-db.com/exploits/49227)