PT-2020-15590 · Projectworlds · Projectworlds Car Rental Management System

Published

2020-10-06

·

Updated

2020-10-14

·

CVE-2020-23832

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Projectworlds Car Rental Management System version 1.0
Description A Persistent Cross-Site Scripting (XSS) issue in the message admin.php file allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.
Recommendations For Projectworlds Car Rental Management System version 1.0, consider disabling access to the message admin.php file until a patch is available to prevent exploitation of the XSS issue. Restrict access to admin login sessions to minimize the risk of session cookie harvesting.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23832

Affected Products

Projectworlds Car Rental Management System