Medium severity6.1NVD Advisory· Published Oct 6, 2020· Updated Jun 17, 2026
CVE-2020-23832
CVE-2020-23832
Description
A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:car_rental_management_system_project:car_rental_management_system:1.0:*:*:*:*:*:*:*
- Projectworlds/Car Rental Management Systemdescription
- Range: = 1.0
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/158795/Car-Rental-Management-System-1.0-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- projectworlds.innvdVendor Advisory
News mentions
0No linked articles in our index yet.