Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-27822. PoCs published by Tushar Vaidya.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Vehicle Parking Management System 1.0 via the 'catename' parameter. The payload injects a script tag that triggers an alert with the user's cookies when viewed in the 'Manage category' section.
Description
A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Vehicle Parking Management System 1.0 via the 'catename' parameter. The payload injects a script tag that triggers an alert with the user's cookies when viewed in the 'Manage category' section.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N