Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-46450 PoC — Inventory Management System 跨站脚本漏洞

Source
Associated Vulnerability
Title:Inventory Management System 跨站脚本漏洞 (CVE-2023-46450)
Description:Inventory Management System是stemword个人开发者的一个库存管理系统。 Inventory Management System 1.0版本存在安全漏洞,该漏洞源于Add supplier功能存在跨站脚本(XSS)漏洞。
Description
 CVE-2023-46450 reference
Readme
# -CVE-2023-46450

> [Description]
> Sourcecodester Free and Open Source inventory management system 1.0 is
> vulnerable to Cross Site Scripting (XSS) via the Add supplier function.
>
> ------------------------------------------
>
> [Additional Information]
> A video POC stored XSS vulnerability exists in the add supplier functionality in free and open source inventory management system.
> Link:  https://youtu.be/LQy0_xIK2q0
>
> ------------------------------------------
>
> [Vulnerability Type]
> Cross Site Scripting (XSS)
>
> ------------------------------------------
>
> [Vendor of Product]
> opensource
>
> ------------------------------------------
>
> [Affected Product Code Base]
> free-and-open-source-inventory-management-system-php-source-code - 1.0000
>
> ------------------------------------------
>
> [Affected Component]
> Add supplier functionality
>
> ------------------------------------------
>
> [Attack Type]
> Remote
>
> ------------------------------------------
>
> [Impact Code execution]
> true
>
> ------------------------------------------
>
> [Attack Vectors]
> Authenticated Stored XSS
>
> ------------------------------------------
>
> [Reference]
> https://youtu.be/LQy0_xIK2q0
>
> ------------------------------------------
>
> [Discoverer]
> Yagyesh K. Tiwari

File Snapshot

[4.0K] /data/pocs/d58d77ead5f1657b5cf3f5d1e27e2c27e5771180 └── [1.3K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.