ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-26680”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-26680
Published
2021-05-26
CVSS:
5.4
ShadowTrackr CVSS:
0.4
Summary:
In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks.