Record summary

CVE-2021-25791 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBOnline Doctor Appointment System 1.0 - 'Multiple' Stored XSSExploitDB exploitby Mohamed habib SmidiNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubMrCraniums/CVE-2021-25791-Multiple-Stored-XSSRepository PoCby MrCraniumsStars: 1Not analyzed2 files

1.6 KiB

GitHub

PoC details

References

4