PT-2020-16929 · Sourcecodester · Sourcecodester Gym Management System

Published

2020-11-17

·

Updated

2025-12-22

·

CVE-2020-28129

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Gym Management System version 1.0
Description A stored Cross-site scripting (XSS) issue allows users to inject and store arbitrary JavaScript code in "index.php?page=packages" via vulnerable fields Package Name and Description.
Recommendations For SourceCodester Gym Management System version 1.0, consider disabling the Package Name and Description fields in the "index.php?page=packages" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the Package Name and Description fields in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-28129

Affected Products

Sourcecodester Gym Management System