VulnerabilityModified
CVE-2020-28927
There is a Stored XSS in Magicpin v2.1 in the User Registration section.
MEDIUM 6.1EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- magicpin/magicpin
- Source
- cve@mitre.org
References
- https://akshayj0111.medium.com/cve-2020-28927-6f64c25239bbExploit, Third Party Advisory
- https://magicpin.inProduct
- https://akshayj0111.medium.com/cve-2020-28927-6f64c25239bbExploit, Third Party Advisory
- https://magicpin.inProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.