CVE-2021-43137: XSS
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this cross-site scripting and cross-site request forgery vulnerability?
The vulnerability ID for this cross-site scripting and cross-site request forgery vulnerability is CVE-2021-43137.
What is the severity rating of CVE-2021-43137?
The severity rating of CVE-2021-43137 is high with a value of 8.8.
What is the affected software by CVE-2021-43137?
The affected software is Hostel Management System Project Hostel Management System version 2.1 and PHPGurukul Hostel Management System version 2.1.
How can the vulnerability be exploited?
The vulnerability can be exploited by submitting malicious input via the name field in my-profile.php, allowing for cross-site scripting and cross-site request forgery attacks.
Is there a known exploit for CVE-2021-43137?
Yes, there is a known exploit for CVE-2021-43137. You can find more information about it at the following link: Exploit-DB - CVE-2021-43137