Files
CVEs-PoC/2020/CVE-2020-28722.md
T
2024-05-25 21:48:12 +02:00

18 lines
662 B
Markdown

### [CVE-2020-28722](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28722)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Deskpro Cloud Platform and on-premise 2020.2.3.48207 from 2020-07-30 contains a cross-site scripting (XSS) vulnerability that can lead to an account takeover via custom email templates.
### POC
#### Reference
- https://www.r29k.com/articles/bb/stored-xss-in-deskpro
#### Github
No PoCs found on GitHub currently.