CVE-2021-46080

MEDIUM

Vehicle Service Management System 1.0 - CSRF

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2021-46080. PoCs published by sanupl, plsanu.

AI-analyzed exploit summary This repository provides a detailed technical writeup of CVE-2021-46080, a CSRF vulnerability in Vehicle Service Management System 1.0 that leads to stored XSS. It includes step-by-step exploitation instructions for multiple endpoints, payloads, and mitigation recommendations.

Description

A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads to Stored Cross Site Scripting Vulnerability.

Exploits (3)

nomisec WRITEUP 1 stars
by sanupl · poc
https://github.com/sanupl/CVE-2021-46080

This repository provides a detailed technical writeup of CVE-2021-46080, a CSRF vulnerability in Vehicle Service Management System 1.0 that leads to stored XSS. It includes step-by-step exploitation instructions for multiple endpoints, payloads, and mitigation recommendations.

Classification
Writeup 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Vehicle Service Management System 1.0
Auth required
Prerequisites: admin access to the target system · Burp Suite for CSRF PoC generation
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WRITEUP
by sanupl · poc
https://github.com/sanupl/Vehicle-Service-Management-System-Multiple-Cross-Site-Request-Forgery-CSRF-Leads-to-XSS

This repository provides a detailed technical writeup of CVE-2021-46080, a CSRF vulnerability in Vehicle Service Management System 1.0 that leads to stored XSS. It includes step-by-step exploitation instructions for multiple endpoints, payload examples, and mitigation recommendations.

Classification
Writeup 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Vehicle Service Management System 1.0
Auth required
Prerequisites: admin access to the target system · Burp Suite for CSRF PoC generation
devstral-2 · analyzed May 19, 2026 Full analysis →
nomisec WRITEUP
by plsanu · poc
https://github.com/plsanu/Vehicle-Service-Management-System-Multiple-Cross-Site-Request-Forgery-CSRF-Leads-to-XSS

This repository provides a detailed writeup of CVE-2021-46080, a CSRF vulnerability in Vehicle Service Management System 1.0 that leads to stored XSS. It includes step-by-step exploitation instructions for multiple endpoints.

Classification
Writeup 100%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Vehicle Service Management System 1.0
Auth required
Prerequisites: Admin access to the target application · Burp Suite for CSRF PoC generation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 4.8
EPSS 0.0058
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-352 CWE-79
Status published
Products (1)
vehicle_service_management_system_project/vehicle_service_management_system < 1.0
Published Jan 06, 2022
Tracked Since Feb 18, 2026