First published: Wed Apr 28 2021(Updated: )
Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Equipment Inventory System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-29387 has a high severity rating due to multiple stored cross-site scripting vulnerabilities that can allow remote attackers to inject malicious scripts.
To fix CVE-2021-29387, you should update the Equipment Inventory System to the latest version or implement input validation and output encoding to sanitize user inputs.
The potential impacts of CVE-2021-29387 include unauthorized access, data theft, and malicious content injection affecting users interacting with the system.
Users of Sourcecodester Equipment Inventory System version 1.0 are affected by CVE-2021-29387.
Yes, CVE-2021-29387 can be exploited remotely, allowing attackers to execute arbitrary JavaScript via specific input fields.