PT-2020-15590 · Projectworlds · Projectworlds Car Rental Management System
Published
2020-10-06
·
Updated
2020-10-14
·
CVE-2020-23832
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Projectworlds Car Rental Management System version 1.0
Description
A Persistent Cross-Site Scripting (XSS) issue in the message admin.php file allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.
Recommendations
For Projectworlds Car Rental Management System version 1.0, consider disabling access to the message admin.php file until a patch is available to prevent exploitation of the XSS issue. Restrict access to admin login sessions to minimize the risk of session cookie harvesting.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projectworlds Car Rental Management System