CVE-2021-28007
MEDIUMWeb Based Quiz System 1.0 - Cross-Site Scripting via Name Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-28007. PoCs published by P.Naveen Kumar.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Web Based Quiz System 1.0 via the 'name' parameter during registration. The payload is injected into the registration form and triggers when viewing the ranking section after attempting a quiz.
Description
Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in register.php through the name parameter.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Web Based Quiz System 1.0 via the 'name' parameter during registration. The payload is injected into the registration form and triggers when viewing the ranking section after attempting a quiz.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N