PT-2020-16187 · Projectworlds · Projectworlds Visitor Management System

Rahul Ramkumar

·

Published

2020-09-29

·

Updated

2026-01-23

·

CVE-2020-25761

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Projectworlds Visitor Management System in PHP version 1.0
Description The issue allows for cross-site scripting (XSS) attacks due to a lack of input validation on request parameters in the myform.php file. An attacker can inject javascript payloads into the parameters to perform various attacks, such as stealing cookies and sensitive information.
Recommendations For Projectworlds Visitor Management System in PHP version 1.0, consider implementing input validation on the request parameters in the myform.php file to prevent XSS attacks. As a temporary workaround, restrict access to the myform.php file until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-25761

Affected Products

Projectworlds Visitor Management System