60 lines
1.9 KiB
JSON
Raw Normal View History

{
"id": "CVE-2020-36085",
"sourceIdentifier": "cve@mitre.org",
"published": "2025-02-06T22:15:33.937",
"lastModified": "2025-02-11T15:15:13.697",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Stored Cross Site Scripting(XSS) vulnerability in Egavilan Media Resumes Management and Job Application Website 1.0 allows remote attackers to inject arbitrary code via First and Last Name in Apply For This Job Form."
},
{
"lang": "es",
"value": "La vulnerabilidad de Cross Site Scripting (XSS) almacenado en Egavilan Media Resumes Management and Job Application Website 1.0 permite a atacantes remotos inyectar c\u00f3digo arbitrario a trav\u00e9s del nombre y apellido en el formulario de solicitud para este empleo."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 2.8,
"impactScore": 3.4
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/manitorpotterk/CVE/blob/main/Egavilan%20Media%20XSS.md",
"source": "cve@mitre.org"
}
]
}