Jeesns · Jeesns · CVE-2020-19285
Name of the Vulnerable Software and Affected Versions:
Jeesns version 1.4.2
Description:
A stored cross-site scripting (XSS) issue exists in the /group/apply component, allowing attackers to execute arbitrary web scripts or HTML via a crafted payload in the `Name` text field.
Recommendations:
For Jeesns version 1.4.2, as a temporary workaround, consider restricting access to the /group/apply component until a patch is available. Avoid using the `Name` text field in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.