Medium severity6.1NVD Advisory· Published Dec 15, 2020· Updated Jun 17, 2026
CVE-2020-35395
CVE-2020-35395
Description
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:egavilanmedia:expense_management_system:1.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:egavilanmedia:expense_management_system:1.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: = 1.0
Patches
Vulnerability mechanics
References
2- nikhilkumar01.medium.com/cve-2020-35395-cd393ac8371cnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/49146nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.