PT-2022-11992 · Sourcecodester · Stock Management System

Published

2022-01-31

·

Updated

2022-02-04

·

CVE-2021-44114

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Stock Management System in PHP/OOP version 1.0
Description A Cross Site Scripting (XSS) issue exists, allowing remote malicious users to execute arbitrary code via the create user function. This enables remote code execution.
Recommendations For version 1.0, consider disabling the create user function until a patch is available to prevent exploitation. Restrict access to this function to minimize the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44114

Affected Products

Stock Management System