First published: Fri Jan 29 2021(Updated: )
PHPGurukul Daily Expense Tracker System 1.0 is vulnerable to stored XSS via the add-expense.php Item parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Daily Expense Tracker System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-26304.
The severity of CVE-2021-26304 is medium with a CVSS score of 5.4.
PHPGurukul Daily Expense Tracker System 1.0 is affected by CVE-2021-26304.
CVE-2021-26304 belongs to the CWE category 79 (Cross-Site Scripting).
To fix the stored XSS vulnerability, update PHPGurukul Daily Expense Tracker System to a version that includes a patch for CVE-2021-26304.