Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-39287-Stored-XSS — CVE-TBD Stored XSS in TastyIgniter v3.0.7 Restaurtant CMS | Kitploit
Tools/GitHubGitHub/fearless523/cve-2021-39287-stored-xss
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubfearless523/cve-2021-39287-stored-xss

CVE-2021-39287-Stored-XSS

CVE-TBD Stored XSS in TastyIgniter v3.0.7 Restaurtant CMS

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
525 years agoNot yet reviewed

CVE-2021-39287-Stored-XSS

CVE-2021-39287 Stored XSS in TastyIgniter v3.0.7 Restaurtant CMS

A stored Cross Site Scripting (XSS) vulnerability exists within TastyIgniter v3.0.7 Restaurant CMS. The description input field, located in /admin/locations/settings is not properly sanitized, and allows arbitrary code to be stored within the site.

Affected Component

URL: /admin/locations/settings

POC

  • Scroll down to "Descriptions"
  • Insert any random sentence, and any arbitraty code: ""
  • Save the page, and a pop up will appear with the sentence All Your Cookie are Belong to Us
  • Refresh, and it will remain.

StoredXSSTastyIgniter

Discovered by

Mike Padrick (Fearless) August 16th, 2021

Download Tool