Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-41962 PoC — Sourcecodester Vehicle Service Management System 跨站脚本漏洞

Source
Associated Vulnerability
Title:Sourcecodester Vehicle Service Management System 跨站脚本漏洞 (CVE-2021-41962)
Description:Sourcecodester Vehicle Service Management System是开源的一个PHP 项目。用于汽车维修/服务店或企业的简单 Web 应用程序。 Sourcecodester Vehicle Service Management System 存在跨站脚本漏洞,攻击者可通过 Vehicle_service 中发送服务请求中的所有者全名参数来进行攻击。
Description
Stored XSS found in Vehicle Service Management System 1.0 application in Sourcecodester.
Readme
# -CVE-2021-41962

>Description
> Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.

> [Additional Information]
> NA


> [Vulnerability Type]
> Cross Site Scripting (XSS)

> [Vendor of Product]
> https://www.sourcecodester.com/

> [Affected Product Code Base]
> Vehicle Service Management System - 1.0
> [Affected Component]
> http://localhost/vehicle_service/

> [Attack Type]
> Remote

> [Impact Information Disclosure]
> true

> [Attack Vectors]
> Steps for reproduce:
> 1. Go to url http://localhost/vehicle_service/ 
> 2. Click on "Send Service Request"
> 3. Enter the payload <script>alert(1)</script> in the "Owner fullname" parameter
> 4. Click on "Submit request"
> 5. Login into admin panel http://localhost/vehicle_service/admin/
> 6. Click on "Service Requests" in the left bar
> 7. The pop up will be triggered.

> [Reference]
> https://owasp.org/www-community/attacks/xss/

> [Discoverer]
> M Lohith

Use CVE-2021-41962.

File Snapshot

[4.0K] /data/pocs/4231daa6c0cabb6b16663d2356c0fe19b2e586ad └── [1.0K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.