PT-2021-16990 · Unknown · Phpgurukul Daily Expense Tracker System
Published
2021-01-29
·
Updated
2021-01-30
·
CVE-2021-26303
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHPGurukul Daily Expense Tracker System version 1.0
Description
The issue concerns a stored XSS vulnerability via the
Full Name field in the user-profile.php page. This allows for malicious scripts to be stored and executed when the page is viewed.Recommendations
For PHPGurukul Daily Expense Tracker System version 1.0, consider validating and sanitizing user input in the
Full Name field to prevent the execution of malicious scripts. As a temporary workaround, restrict access to the user-profile.php page until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Daily Expense Tracker System