Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-14427. PoCs published by Metin Yunus Kandemir.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Web Studio Ultimate Loan Manager V2.0 by injecting a malicious script into the 'notes' parameter during branch creation. The payload is URL-encoded and submitted via a POST request to the '/branch/store' endpoint.
Description
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Web Studio Ultimate Loan Manager V2.0 by injecting a malicious script into the 'notes' parameter during branch creation. The payload is URL-encoded and submitted via a POST request to the '/branch/store' endpoint.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N