PT-2022-11629 · Php+1 · Php+1

Pecho Kobadinski

·

Published

2022-09-16

·

Updated

2022-09-20

·

CVE-2021-42597

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Storage Unit Rental Management System version 1.0 PHP versions 8.0.10 Apache versions 2.4.14
Description A Cross Site Scripting (XSS) issue exists via the Add New Tenant List Rent List form. This allows for potential malicious script execution.
Recommendations For Sourcecodester Storage Unit Rental Management System version 1.0, consider disabling the Add New Tenant List Rent List form until a patch is available. For PHP versions 8.0.10, update to a newer version to mitigate the risk. For Apache versions 2.4.14, update to a newer version to mitigate the risk.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42597

Affected Products

Apache
Php