
CVE-2021-46072 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.
"><script>alert(document.cookie)</script>
An attacker can able to inject malicious JavaScript code in Service List Section.
It is recommended to sanitize all the input fields throughout the application.