CVE-2021-25790

Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.
Configurations

Configuration 1 (hide)

cpe:2.3:a:house_rental_and_property_listing_php_project:house_rental_and_property_listing_php:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:55

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/49352 - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/49352 - Exploit, Third Party Advisory, VDB Entry
References () https://www.sourcecodester.com - Product () https://www.sourcecodester.com - Product
References () https://www.sourcecodester.com/php/14649/house-rental-and-property-listing-php-full-source-code.html - Product () https://www.sourcecodester.com/php/14649/house-rental-and-property-listing-php-full-source-code.html - Product

Information

Published : 2021-07-23 18:15

Updated : 2024-11-21 05:55


NVD link : CVE-2021-25790

Mitre link : CVE-2021-25790

CVE.ORG link : CVE-2021-25790


JSON object : View

Products Affected

house_rental_and_property_listing_php_project

  • house_rental_and_property_listing_php
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')