Beveiligingsadvies

CVE-2020-26680

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-05-26 11:54:59
Laatst bijgewerkt 2026-07-09 00:11:30
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.