CVE-2021-40577
MEDIUMSourcecodester Online Enrollment Management System - XSS
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-40577. PoCs published by Tushar Jadhav.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the Online Enrollment Management System 1.0, where an attacker can inject malicious JavaScript into the 'U_NAME' parameter during user registration, which executes when viewed by an admin or user.
Description
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in the Online Enrollment Management System 1.0, where an attacker can inject malicious JavaScript into the 'U_NAME' parameter during user registration, which executes when viewed by an admin or user.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N