PT-2021-11743 · Unknown · Employee Performance Evaluation System

Published

2021-01-20

·

Updated

2021-01-27

·

CVE-2020-35271

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Employee Performance Evaluation System in PHP/MySQLi with Source Code version 1.0
Description: The issue concerns cross-site scripting (XSS) in the Employees, First Name, and Last Name fields. This means that an attacker could potentially inject malicious scripts into these fields, which could then be executed by the application, leading to unauthorized actions or data exposure.
Recommendations: For Employee Performance Evaluation System in PHP/MySQLi with Source Code version 1.0, consider validating and sanitizing user input in the Employees, First Name, and Last Name fields to prevent XSS attacks. As a temporary workaround, restrict access to these fields until a proper fix is implemented.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-35271

Affected Products

Employee Performance Evaluation System