First published: Fri Nov 05 2021(Updated: )
A Stored Cross Site Scripting (XSS) Vulneraibiilty exists in Sourcecodester Engineers Online Portal in PHP via the (1) Quiz title and (2) quiz description parameters to add_quiz.php. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Engineers Online Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42664 is a Stored Cross Site Scripting (XSS) vulnerability in the Sourcecodester Engineers Online Portal.
CVE-2021-42664 allows an attacker to run malicious JavaScript commands on the web server using the Quiz title and quiz description parameters in the add_quiz.php endpoint.
CVE-2021-42664 has a severity score of 5.4, which is considered medium.
The affected software is the Engineers Online Portal Project Engineers Online Portal version 1.0.
To fix CVE-2021-42664, it is recommended to update the Sourcecodester Engineers Online Portal to a patched version provided by the vendor.