First published: Wed Sep 28 2022(Updated: )
A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Expense Management System Project Expense Management System | =1.0 | |
Oretnom23 Expense Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-41434 is medium.
CVE-2021-41434 is a stored Cross-Site Scripting (XSS) vulnerability.
Version 1.0 of the Expense Management System application is affected by CVE-2021-41434.
An attacker can exploit CVE-2021-41434 by executing arbitrary JavaScript commands through index.php.
There is no specific fix available for CVE-2021-41434, but updating to a patched version of the Expense Management System application may resolve the vulnerability.