CVE-2020-23831
A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and session cookies when an unauthenticated victim clicks on a…
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and session cookies when an unauthenticated victim clicks on a malicious URL and enters credentials.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- stock management system project/stock management system
- Source
- cve@mitre.org
References
- https://github.com/boku7/StockManagement-XSS-Login-CredHarvesterExploit, Third Party Advisory
- https://packetstormsecurity.com/files/158813/Tailor-MS-1.0-Cross-Site-Scripting.htmlExploit, Third Party Advisory
- https://github.com/boku7/StockManagement-XSS-Login-CredHarvesterExploit, Third Party Advisory
- https://packetstormsecurity.com/files/158813/Tailor-MS-1.0-Cross-Site-Scripting.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.