{"id":"CVE-2020-24390","details":"eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow pre-authentication stored XSS during login/logout logs recording.","modified":"2026-07-09T00:06:41.396839Z","published":"2020-08-27T16:15:11.503Z","references":[{"type":"ADVISORY","url":"https://github.com/EyesOfNetworkCommunity/eonweb/releases/tag/5.3-7"},{"type":"FIX","url":"https://github.com/EyesOfNetworkCommunity/eonweb/commit/c416b52d3b500d96ab40875f95b7c7939628854b"},{"type":"FIX","url":"https://www.eyesofnetwork.com/fr/news/fr-CVE-2020-24390"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eyesofnetworkcommunity/eonweb","events":[{"introduced":"0"},{"fixed":"71e23ee4cb7baa20b1654cfdd326d6ca22e2249f"},{"fixed":"c416b52d3b500d96ab40875f95b7c7939628854b"},{"fixed":"b43c5c3f8a9f0b29ba609037bacaaac537f4aa99"}],"database_specific":{"cpe":"cpe:2.3:a:eyesofnetwork:eyesofnetwork:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"5.3"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["5.3-6","5.3-5","5.3-4","5.3-3","5.3-2","4.3-0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24390.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}