Home Embedded Vulns General Vulns

CVE-2020-28930

MEDIUM 5.4

Our Analysis: Environment Specific

Our model has classified this vulnerability as relevant to Environment Specific Systems, helping your team prioritize efforts effectively.

Published Date December 16, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.

Potentially Affected Vendors