PT-2020-16187 · Projectworlds · Projectworlds Visitor Management System
Rahul Ramkumar
·
Published
2020-09-29
·
Updated
2026-01-23
·
CVE-2020-25761
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Projectworlds Visitor Management System in PHP version 1.0
Description
The issue allows for cross-site scripting (XSS) attacks due to a lack of input validation on request parameters in the myform.php file. An attacker can inject javascript payloads into the parameters to perform various attacks, such as stealing cookies and sensitive information.
Recommendations
For Projectworlds Visitor Management System in PHP version 1.0, consider implementing input validation on the request parameters in the myform.php file to prevent XSS attacks. As a temporary workaround, restrict access to the myform.php file until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Projectworlds Visitor Management System