CVE-2021-34073
MEDIUMGadget Works Online Ordering System 1.0 - Cross-Site Scripting via Category Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-34073. PoCs published by Vinay H C.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in Gadget Works Online Ordering System 1.0. The vulnerability allows an attacker to inject malicious scripts into the 'Category' input field, which executes when users access the affected page.
Description
A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in Gadget Works Online Ordering System 1.0. The vulnerability allows an attacker to inject malicious scripts into the 'Category' input field, which executes when users access the affected page.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N