Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-26832 — Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site. | Kitploit
Tools/GitHubGitHub/gal-nagli/cve-2021-26832
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubgal-nagli/cve-2021-26832

CVE-2021-26832

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site.

View Repository
5325 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-26832

[Suggested description] Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site.


[Vulnerability Type] Cross Site Scripting (XSS)


[Vendor of Product] https://www.priority-software.com/il/


[Affected Product Code Base] Priority Enterprise Management System - Version 8.00


[Affected Component] Reset password page form


[Attack Type] Remote


[CVE Impact Other] Javascript execution on the victims behalf


[Attack Vectors] To exploit the vulnerability, the victim needs to click on a crafted link or webpage, which will initiate the CSRF request on his behalf.


[Reference] https://galnagli.com / https://github.com/NagliNagli/CVE-2021-26832


[Discoverer] Gal Nagli

Download Tool