Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown

CVE-2020-35276

Disclosure Date: December 21, 2020 (last updated November 28, 2024)
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
Attacker Value
Unknown

CVE-2020-35273

Disclosure Date: December 21, 2020 (last updated November 28, 2024)
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.
Attacker Value
Unknown

CVE-2020-35395

Disclosure Date: December 15, 2020 (last updated November 28, 2024)
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
Attacker Value
Unknown

CVE-2020-35396

Disclosure Date: December 15, 2020 (last updated November 28, 2024)
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.