nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25791 CVE-2021-25791
MEDIUM
Online Doctor Appointment System 1.0 - 'Multiple' Stored XSS
Record summary
CVE-2021-25791 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBOnline Doctor Appointment System 1.0 - 'Multiple' Stored XSSExploitDB exploitby Mohamed habib SmidiNot analyzed1 file
Repository PoCs
GitHubMrCraniums/CVE-2021-25791-Multiple-Stored-XSSRepository PoCby MrCraniumsStars: 1Not analyzed2 files
References
4exploit-db.com
https://www.exploit-db.com/exploits/49396 sourcecodester.com
https://www.sourcecodester.com/ sourcecodester.com
https://www.sourcecodester.com/php/14663/online-doctor-appointment-system-php-full-source-code.html