01642 06 11 11 Arrange Call

Cross-Site Scripting (XSS) Vulnerability in vFairs 3.3 Allows Profile Modification and Payload Injection

CVE-2020-26680 · MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CVE-2020-26680

In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.

Learn more about our User Device Pen Test.