PT-2021-23458 · Sourcecodester · Sourcecodester Vehicle Service Management System
Lohyt
+1
·
Published
2021-12-16
·
Updated
2021-12-20
·
CVE-2021-41962
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sourcecodester Vehicle Service Management System version 1.0
Description
A Cross Site Scripting (XSS) issue exists in the system via the
fullname parameter in a Send Service Request in vehicle service. This allows for potential malicious script execution.Recommendations
For Sourcecodester Vehicle Service Management System version 1.0, consider validating and sanitizing the
fullname parameter to prevent XSS attacks. As a temporary workaround, restrict access to the Send Service Request feature in vehicle service until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Vehicle Service Management System