CVE-2021-42663

MEDIUM NUCLEI

Online Event Booking And Reservation System - XSS

Title source: rule

Description

An HTML injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the msg parameter to /event-management/index.php. An attacker can leverage this vulnerability in order to change the visibility of the website. Once the target user clicks on a given link he will display the content of the HTML code of the attacker's choice.

Exploits (2)

nomisec WRITEUP 1 stars
by 0xDeku · poc
https://github.com/0xDeku/CVE-2021-42663
inthewild WRITEUP
poc
https://github.com/thehackingrabbi/cve-2021-42663

Nuclei Templates (1)

Sourcecodester Online Event Booking and Reservation System 2.3.0 - Cross-Site Scripting
MEDIUMVERIFIEDby fxploit

Scores

CVSS v3 4.3
EPSS 0.3798
EPSS Percentile 97.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-79
Status published
Products (1)
online_event_booking_and_reservation_system_project/online_event_booking_and_reservation_system 2.3.0
Published Nov 05, 2021
Tracked Since Feb 18, 2026