CVE-2020-28071 CWE-79 Varies High
Exploit Alert High Remote 2020-12-18
Alumni Management System 1.0 Cross Site Scripting
# Exploit Title: Stored XSS on Alumni Management System 
# Date: 23/10/2020
# Exploit Author: Valerio Alessandroni
# Vendor Homepage:
# Software Link: ource-code.html
# Version: 1.0
# Tested on: ubuntu 18.04
# CVE : CVE-2020-28071
# Description:
An attacker after the admin authentication, can upload an image in the gallery, using a XSS payload in the description textarea called "about" and reach a stored XSS.
# Reproduction:
- Login as "admin"
- upload an image in the gallery area in the administration panel injecting Javascript code in the textarea called "about"
- The obtained XSS affects the administration panel (ex: and
the public gallery (ex:

