Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-25791 PoC — Online Doctor Appointment System 跨站脚本漏洞

Source
Associated Vulnerability
Title:Online Doctor Appointment System 跨站脚本漏洞 (CVE-2021-25791)
Description:Online Doctor Appointment System是一个使用 PHP、JavaScript 和 CSS 开发的在线预约医生系统。 Online Doctor Appointment System 1.0存在跨站脚本漏洞,该漏洞允许经过身份验证的攻击者通过“更新配置文件”模块中的名字、姓氏和地址文本字段中精心设计的有效负载执行任意 Web 脚本或 HTML。
Description
Multiple Stored XSS Online Doctor Appointment System 
Readme
# CVE-2021-25791-Multiple-Stored-XSS : Multiple Stored XSS Online Doctor Appointment System 
Multiple stored aunthenticated cross-site scripting exists in the Online Doctor Appointment System V1.0
Software Link: https://www.sourcecodester.com/download-code?nid=14663&title=Online+Doctor+Appointment+System+in+PHP+with+Full+Source+Code


https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25791

https://nvd.nist.gov/vuln/detail/CVE-2021-25791

## POC 
https://www.exploit-db.com/exploits/49396


## Discovery
- January 2021
- Mohamed habib Smidi | Craniums .
File Snapshot

[4.0K] /data/pocs/108d5e60308144d64d0d152998818f5182efc44d ├── [1.0K] LICENSE └── [ 564] README.md 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.