CVE-2021-41962

MEDIUM

Sourcecodester Vehicle Service Management System 1.0 - Stored Cross-Site Scripting via Owner Fullname Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-41962. PoCs published by lohyt.

AI-analyzed exploit summary This repository contains a writeup describing a stored XSS vulnerability in Sourcecodester Vehicle Service Management System 1.0. The vulnerability allows an attacker to inject malicious scripts via the 'Owner fullname' parameter, which executes when viewed in the admin panel.

Description

Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.

Exploits (1)

nomisec WRITEUP
by lohyt · poc
https://github.com/lohyt/-CVE-2021-41962

This repository contains a writeup describing a stored XSS vulnerability in Sourcecodester Vehicle Service Management System 1.0. The vulnerability allows an attacker to inject malicious scripts via the 'Owner fullname' parameter, which executes when viewed in the admin panel.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Vehicle Service Management System 1.0
No auth needed
Prerequisites: Access to the 'Send Service Request' form
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/lohyt/-CVE-2021-41962

Scores

CVSS v3 4.8
EPSS 0.0060
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
vehicle_service_management_system_project/vehicle_service_management_system 1.0
Published Dec 16, 2021
Tracked Since Feb 18, 2026