VYPR
Unrated severityNVD Advisory· Published Sep 9, 2021· Updated Aug 4, 2024

CVE-2020-19285

CVE-2020-19285

Description

A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Jeesns 1.4.2 has a stored XSS vulnerability in the /group/apply component via the Name field, allowing arbitrary script execution.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the /group/apply component of Jeesns version 1.4.2. The Name text field fails to sanitize user input, enabling an attacker to inject arbitrary web scripts or HTML. This flaw is documented in the Seebug vulnerability database [1].

Exploitation

An attacker must have access to the group application functionality. By submitting a crafted payload in the Name field, the malicious script is stored on the server. When an administrator or other user views the group application list or details, the script executes in their browser.

Impact

Successful exploitation allows arbitrary JavaScript execution in the context of the victim's browser. This can lead to session hijacking, defacement, or theft of sensitive data. The impact is confined to users who view the affected page.

Mitigation

No official patch has been released for Jeesns 1.4.2 as of the publication date (2021-09-09). Users should upgrade to a newer version if available, or implement input validation and output encoding for the Name field. The vulnerability is listed on Seebug [1] but no fix is provided.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.