Lucene search

K
cvelistMitreCVELIST:CVE-2021-42664
HistoryNov 05, 2021 - 12:19 p.m.

CVE-2021-42664

2021-11-0512:19:00
mitre
www.cve.org
5
stored cross site scripting
sourcecodester
engineers online portal
php
add_quiz.php
web server
cookie stealing

EPSS

0.002

Percentile

54.3%

A Stored Cross Site Scripting (XSS) Vulneraibiilty exists in Sourcecodester Engineers Online Portal in PHP via the (1) Quiz title and (2) quiz description parameters to add_quiz.php. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.

EPSS

0.002

Percentile

54.3%