CVE-2020-28071
23.12.2020, 18:15
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.
Vendor | Product | Version |
---|---|---|
alumni_management_system_project | alumni_management_system | 1.0 |
𝑥
= Vulnerable software versions