Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-99653
HistoryNov 08, 2021 - 12:00 a.m.

Sourcecodester Engineers Online Portal Cross-Site Scripting Vulnerability

2021-11-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
sourcecodester
engineers
online
portal
cross-site scripting
vulnerability
php
attacker
exploit
javascript
commands
cookie theft
open source

EPSS

0.002

Percentile

54.3%

Sourcecodester Engineers Online Portal is an open source online portal. sourcecodester Engineers Online Portal in PHP is vulnerable to a cross-site scripting vulnerability. An attacker can exploit the vulnerability to run javascript commands via the add_quiz.php quiz title and quiz description parameters, leading to cookie theft.

EPSS

0.002

Percentile

54.3%