Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-46824. PoCs published by Pintu Solanki.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in School File Management System 1.0 via the 'Firstname' and 'Lastname' fields in the 'Update Account' functionality. The payload injects a script that executes when the vulnerable page is accessed.
Description
Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in School File Management System 1.0 via the 'Firstname' and 'Lastname' fields in the 'Update Account' functionality. The payload injects a script that executes when the vulnerable page is accessed.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N