There is a Stored XSS in Magicpin v2.1 in the User Registration section. Each time an admin visits the manage user section from the admin panel, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-11-23T19:36:04
Updated: 2024-08-04T16:47:59.919Z
Reserved: 2020-11-18T00:00:00
Link: CVE-2020-28927
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-11-23T20:15:12.900
Modified: 2020-11-30T17:19:41.720
Link: CVE-2020-28927
Redhat
No data.