PT-2021-11743 · Unknown · Employee Performance Evaluation System
Published
2021-01-20
·
Updated
2021-01-27
·
CVE-2020-35271
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Employee Performance Evaluation System in PHP/MySQLi with Source Code version 1.0
Description:
The issue concerns cross-site scripting (XSS) in the Employees, First Name, and Last Name fields. This means that an attacker could potentially inject malicious scripts into these fields, which could then be executed by the application, leading to unauthorized actions or data exposure.
Recommendations:
For Employee Performance Evaluation System in PHP/MySQLi with Source Code version 1.0, consider validating and sanitizing user input in the Employees, First Name, and Last Name fields to prevent XSS attacks. As a temporary workaround, restrict access to these fields until a proper fix is implemented.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Employee Performance Evaluation System