CVE-2021-26304: XSS
Published Jan 29, 2021
·Updated
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.
Affected Software
1 affected component
Phpgurukul Daily Expense Tracker System=1.0
Event History
Jan 29, 2021
CVE Published
via MITRE·01:48 AM
Data Sourced
via MITRE·01:48 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-26304.
2
What is the severity of CVE-2021-26304?
The severity of CVE-2021-26304 is medium with a CVSS score of 5.4.
3
Which software is affected by CVE-2021-26304?
PHPGurukul Daily Expense Tracker System 1.0 is affected by CVE-2021-26304.
4
What is the CWE category for CVE-2021-26304?
CVE-2021-26304 belongs to the CWE category 79 (Cross-Site Scripting).
5
How can I fix the stored XSS vulnerability in PHPGurukul Daily Expense Tracker System 1.0?
To fix the stored XSS vulnerability, update PHPGurukul Daily Expense Tracker System to a version that includes a patch for CVE-2021-26304.