Files
CVEs-PoC/2020/CVE-2020-28047.md
T
2024-05-25 21:48:12 +02:00

805 B

CVE-2020-28047

Description

AudimexEE before 14.1.1 is vulnerable to Reflected XSS (Cross-Site-Scripting). If the recommended security configuration parameter "unique_error_numbers" is not set, remote attackers can inject arbitrary web script or HTML via 'action, cargo, panel' parameters that can lead to data leakage.

POC

Reference

Github