CVE-2021-42662
MEDIUMSourcecodester Online Event Booking and Reservation System - Stored Cross-Site Scripting via Holiday Reason Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2021-42662. PoCs published by Alon Leviev, 0xDeku.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in the 'reason' parameter of the Online Event Booking and Reservation System 1.0. The payload is injected via a POST request to the holiday endpoint, leading to arbitrary JavaScript execution in the context of the victim's browser.
Description
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
Exploits (3)
This exploit demonstrates a stored XSS vulnerability in the 'reason' parameter of the Online Event Booking and Reservation System 1.0. The payload is injected via a POST request to the holiday endpoint, leading to arbitrary JavaScript execution in the context of the victim's browser.
This repository contains a proof-of-concept for CVE-2021-42662, a stored XSS vulnerability in the Online Event Booking and Reservation System version 2.3.0. The exploit leverages the 'reason' parameter in the HOLY page to execute arbitrary JavaScript code.
This repository provides a technical description and proof-of-concept for a stored XSS vulnerability in the Online Event Booking and Reservation System version 2.3.0. The vulnerability allows an attacker to inject malicious JavaScript via the 'reason' parameter on the HOLY page.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N