First published: Wed Oct 27 2021(Updated: )
A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Vehicle Parking Management System Project Vehicle Parking Management System | =1.0 | |
PHPGurukul Vehicle Parking Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2021-37805.
The severity level of CVE-2021-37805 is medium with a score of 5.4.
The impact of the Stored Cross Site Scripting (XSS) vulnerability in this issue allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions, data theft, or session hijacking.
To fix the Stored Cross Site Scripting (XSS) vulnerability in Sourcecodeste Vehicle Parking Management System 1.0, it is recommended to ensure proper input validation and sanitization of user-supplied data on the add-vehicle.php endpoint, as well as implementing output encoding to prevent script execution.
More information about CVE-2021-37805 can be found at the following reference link: [Vehicle-Parking-Management-System-1.0-Cross-Site-Scripting](https://packetstormsecurity.com/files/163625/Vehicle-Parking-Management-System-1.0-Cross-Site-Scripting.html)