Record summary

CVE-2021-46005 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Proofs of concept

2

Catalogued exploits

ExploitDBOnline Car Rental System 1.0 - Stored Cross Site ScriptingExploitDB exploitby Naved ShaikhNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubnawed20002/CVE-2021-46005Repository PoCby nawed20002Stars: 0Not analyzed1 file

1.3 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMSourcecodester Car Rental Management System 1.0 - Stored Cross-Site ScriptingCVSS 5.4

Sourcecodester Car Rental Management System 1.0 is vulnerable to cross-site scripting via the vehicalorcview parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the application, leading to the execution of arbitrary code or theft of sensitive information.

Remediation

To remediate this issue, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.

WeaknessesCWE-79
Authorscckuailong
Template tagscve2021cvesourcecodesterauthenticatededbxssintrusivecar_rental_management_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:car_rental_management_system_project:car_rental_management_system:1.0:*:*:*:*:*:*:*
Shodan: http.html:"car rental management system"
FOFA: body="car rental management system"

Source: ProjectDiscovery

References

3