PT-2021-17500 · Unknown · Phpgurukul Beauty Parlour Management System

Published

2021-04-15

·

Updated

2023-11-14

·

CVE-2021-27544

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Beauty Parlour Management System version 1.0
Description The issue allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the sername parameter in the "add-services.php" component. This enables attackers to perform Cross Site Scripting (XSS) attacks.
Recommendations For PHPGurukul Beauty Parlour Management System version 1.0, consider restricting access to the "add-services.php" component until a patch is available, and avoid using the sername parameter in this component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-27544

Affected Products

Phpgurukul Beauty Parlour Management System