CVE-2021-43137
01.12.2021, 20:15
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.
Vendor | Product | Version |
---|---|---|
phpgurukul | hostel_management_system | 2.1 |
𝑥
= Vulnerable software versions