peter bassill · operator
$ cve CVE-2020-35416 JSON

CVE-2020-35416 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 2.7% (pctl 86)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admin login webpage (with different request parameters), allows remote attackers to inject arbitrary web script or HTML.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS2.71% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2020-12-15
Last modified2026-06-17

Affected (1)

VendorProduct
onlineonlyphpjabbers appointment scheduler

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD