PT-2021-5955 · Unknown · Sourcecodester Online Enrollment Management System

Published

2021-08-31

·

Updated

2021-12-03

·

CVE-2021-40577

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code version 1.0
Description A Stored Cross Site Scripting (XSS) issue exists in the Add-Users page via the Name parameter, allowing a remote attacker to perform cross-site scripting attacks.
Recommendations For Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code version 1.0, consider disabling the Name parameter in the Add-Users page as a temporary workaround until a patch is available. Restrict access to the Add-Users page to minimize the risk of exploitation. Avoid using the Name parameter in the affected page until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00472
CVE-2021-40577

Affected Products

Sourcecodester Online Enrollment Management System