vendor:
User Registration & Login and User Management System With admin panel
by:
yusufmalikul
8.8
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: User Registration & Login and User Management System With admin panel
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:phpgurukul:user_registration_&_login_and_user_management_system_with_admin_panel:2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
User Registration & Login and User Management System With admin panel 2.1 – Persistent XSS
User Registration & Login and User Management System With admin panel 2.1 application from PHPgurukul is vulnerable to Persistent XSS via the fname, lname, email, and contact field name when user register on the site then admin viewing user list on manage user page triggering the payload.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.