CVE-2021-41962
MEDIUMSourcecodester Vehicle Service Management System 1.0 - Stored Cross-Site Scripting via Owner Fullname Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-41962. PoCs published by lohyt.
AI-analyzed exploit summary This repository contains a writeup describing a stored XSS vulnerability in Sourcecodester Vehicle Service Management System 1.0. The vulnerability allows an attacker to inject malicious scripts via the 'Owner fullname' parameter, which executes when viewed in the admin panel.
Description
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.
Exploits (1)
This repository contains a writeup describing a stored XSS vulnerability in Sourcecodester Vehicle Service Management System 1.0. The vulnerability allows an attacker to inject malicious scripts via the 'Owner fullname' parameter, which executes when viewed in the admin panel.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N