Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.
History

Thu, 17 Oct 2024 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Adrianmercurio
Adrianmercurio gym Management System
CPEs cpe:2.3:a:gym_management_system_project:gym_management_system:1.0:*:*:*:*:*:*:* cpe:2.3:a:adrianmercurio:gym_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Gym Management System Project
Gym Management System Project gym Management System
Adrianmercurio
Adrianmercurio gym Management System

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-11-17T20:15:30

Updated: 2024-08-04T16:33:57.569Z

Reserved: 2020-11-02T00:00:00

Link: CVE-2020-28129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-17T21:15:12.957

Modified: 2024-11-21T05:22:23.317

Link: CVE-2020-28129

cve-icon Redhat

No data.