Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability allows an attacker to retrieve the session details of an authenticated user.
📦
framework
Vendor: adive
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
5
Total Indexed
Avg. EPSS
0.26%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.6
CVSS
Severity: HIGH
7.6
CVSS
Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker could retrieve the session details of an authenticated user.
Severity: HIGH
8.8
CVSS
CVE-2020-7991
Exploit Found
Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password.
Severity: HIGH
6.1
CVSS
6.1
CVSS
Adive Framework 2.0.8 has admin/user/add userUsername XSS.
Severity: MEDIUM