CVE-2021-34073

MEDIUM

Gadget Works Online Ordering System 1.0 - Cross-Site Scripting via Category Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-34073. PoCs published by Vinay H C.

AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in Gadget Works Online Ordering System 1.0. The vulnerability allows an attacker to inject malicious scripts into the 'Category' input field, which executes when users access the affected page.

Description

A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.

Exploits (1)

exploitdb WRITEUP
by Vinay H C · textwebappsphp
https://www.exploit-db.com/exploits/49904

This is a writeup describing a stored XSS vulnerability in Gadget Works Online Ordering System 1.0. The vulnerability allows an attacker to inject malicious scripts into the 'Category' input field, which executes when users access the affected page.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Gadget Works Online Ordering System 1.0
Auth required
Prerequisites: Admin access to the application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49904

Scores

CVSS v3 5.4
EPSS 0.0058
EPSS Percentile 43.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
gadget_works_online_ordering_system_project/gadget_works_online_ordering_system 1.0
Published Jan 28, 2022
Tracked Since Feb 18, 2026