CVE-2020-35395

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
15/12/2020
Last modified:
16/12/2020

Description

XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:egavilanmedia:expense_management_system:1.0:*:*:*:*:*:*:*