Stored Cross-Site Scripting (XSS) Vulnerabilities in Sage EasyPay 10.7.5.10 through Unicode Transformations

Stored Cross-Site Scripting (XSS) Vulnerabilities in Sage EasyPay 10.7.5.10 through Unicode Transformations

CVE-2020-13893 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Multiple stored cross-site scripting (XSS) vulnerabilities in Sage EasyPay 10.7.5.10 allow authenticated attackers to inject arbitrary web script or HTML via multiple parameters through Unicode Transformations (Best-fit Mapping), as demonstrated by the full-width variants of the less-than sign (%EF%BC%9C) and greater-than sign (%EF%BC%9E).

Learn more about our Web App Pen Testing.