← Back to CVE List

CVE-2020-26680

Published: 2021-05-26T12:15Z
Last Modified: 2024-11-21T05:20Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In vFairs 3.3, any user logged in to a vFairs virtual conference or event can modify any other users profile information to include a cross-site scripting payload. The user data stored by the database includes HTML tags that are intentionally rendered out onto the page, and this can be abused to perform XSS attacks. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt