CVE-2021-46079

HIGH

Sourcecodester Vehicle Service Mgmt 1.0 - File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2021-46079. PoCs published by sanupl, plsanu.

AI-analyzed exploit summary This repository provides a detailed technical writeup on CVE-2021-46079, an unrestricted file upload vulnerability in Sourcecodester Vehicle Service Management System 1.0. It describes multiple attack vectors for HTML injection via file uploads in different admin panel sections.

Description

An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection.

Exploits (3)

nomisec WRITEUP 1 stars
by sanupl · poc
https://github.com/sanupl/CVE-2021-46079

This repository provides a detailed technical writeup on CVE-2021-46079, an unrestricted file upload vulnerability in Sourcecodester Vehicle Service Management System 1.0. It describes multiple attack vectors for HTML injection via file uploads in different admin panel sections.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Vehicle Service Management System 1.0
Auth required
Prerequisites: admin access to the target system
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WRITEUP
by sanupl · poc
https://github.com/sanupl/Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Html-Injection

This repository provides a detailed technical writeup for CVE-2021-46079, an unrestricted file upload vulnerability in Sourcecodester Vehicle Service Management System 1.0. It includes step-by-step exploitation instructions and payloads for multiple endpoints, demonstrating HTML injection via malicious file uploads.

Classification
Writeup 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Vehicle Service Management System 1.0
Auth required
Prerequisites: admin access to the target system · ability to upload files via the admin panel
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WRITEUP
by plsanu · poc
https://github.com/plsanu/Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Html-Injection

This repository provides a detailed writeup for CVE-2021-46079, an unrestricted file upload vulnerability in Sourcecodester Vehicle Service Management System 1.0. It describes multiple endpoints where HTML injection can occur via malicious file uploads.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Sourcecodester Vehicle Service Management System 1.0
Auth required
Prerequisites: Admin access to the Vehicle Service Management System
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.2
EPSS 0.0331
EPSS Percentile 87.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
vehicle_service_management_system_project/vehicle_service_management_system < 1.0
Published Jan 06, 2022
Tracked Since Feb 18, 2026