Skip to content

CVE-2021-42662 - Stored Cross-Site Scripting vulnerability in the Online event booking and reservation system.

Notifications You must be signed in to change notification settings

0xDeku/CVE-2021-42662

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 

Repository files navigation

CVE-2021-42662

CVE-2021-42662 - Stored Cross-Site Scripting vulnerability in the Online event booking and reservation system version 2.3.0.

Technical description:

A stored XSS vulnerability exists in the Event management software version 2.3.0. An attacker can leverage this vulnerability in order to run javascript on the web server surfers behalf, which can lead to cookie stealing, defacement and more.

Affected components -

Vulnerable page - HOLY

Vulnerable parameter - "reason"

Steps to exploit:

  1. Navigate to http://localhost/event-management/views/?v=HOLY
  2. Insert your payload in the "reason" parameter
  3. Click "Add holiday"

Proof of concept (Poc) -

The following payload will allow you to run the javascript code -

<script>alert("This is an XSS")</alert>

CVE-2021-42662

References -

https://www.exploit-db.com/exploits/50450

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42662

https://nvd.nist.gov/vuln/detail/CVE-2021-42662

Discovered by -

Alon Leviev(0xDeku), 22 October, 2021.

About

CVE-2021-42662 - Stored Cross-Site Scripting vulnerability in the Online event booking and reservation system.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages