CVE-2019-25265
MEDIUMOnline Inventory Manager 3.2 - Stored Cross-Site Scripting in Group Description Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25265. PoCs published by Cemal Cihad ÇİFTÇİ.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Online Inventory Manager 3.2. The payload is injected into the description field of the editgroups section, triggering when viewed.
Description
Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Online Inventory Manager 3.2. The payload is injected into the description field of the editgroups section, triggering when viewed.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N