CVE-2020-36085

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Feb 6, 2025
Updated: Feb 11, 2025
CWE ID 79

Summary

CVE-2020-36085 is a stored Cross-Site Scripting (XSS) vulnerability affecting the Egavilan Media Resumes Management and Job Application Website version 1.0. An attacker can exploit this flaw by injecting malicious code into the First and Last Name fields in the "Apply For This Job" form. Successful exploitation allows the attacker to execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, data theft, or phishing attacks. Users are advised to avoid using unpatched versions of the website and to apply security updates as soon as they become available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share