CVE-2021-46005
MEDIUMNuclei
Online Car Rental System 1.0 - Stored Cross Site Scripting
Record summary
CVE-2021-46005 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Proofs of concept
2Catalogued exploits
ExploitDBOnline Car Rental System 1.0 - Stored Cross Site ScriptingExploitDB exploitby Naved ShaikhNot analyzed1 file
Repository PoCs
GitHubnawed20002/CVE-2021-46005Repository PoCby nawed20002Stars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMSourcecodester Car Rental Management System 1.0 - Stored Cross-Site ScriptingCVSS 5.4
Sourcecodester Car Rental Management System 1.0 is vulnerable to cross-site scripting via the vehicalorcview parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the application, leading to the execution of arbitrary code or theft of sensitive information.
Remediation
To remediate this issue, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.
WeaknessesCWE-79
Authorscckuailong
Template tagscve2021cvesourcecodesterauthenticatededbxssintrusivecar_rental_management_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:car_rental_management_system_project:car_rental_management_system:1.0:*:*:*:*:*:*:*
Shodan: http.html:"car rental management system"
FOFA: body="car rental management system"
https://www.exploit-db.com/exploits/49546 https://nvd.nist.gov/vuln/detail/CVE-2021-46005 https://www.sourcecodester.com/cc/14145/online-car-rental-system-using-phpmysql.html https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-46005 exploit-db.com
https://www.exploit-db.com/exploits/49546 sourcecodester.com
https://www.sourcecodester.com/cc/14145/online-car-rental-system-using-phpmysql.html