Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Vehicle-Service-Management-System-Service-List-Stored-Cross-Site-Scripting-XSS — CVE-2021-46072 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel. | Kitploit
Tools/GitHubGitHub/sanupl/vehicle-service-management-system-service-list-stored-cross-site-scripting-xss
Web Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubsanupl/vehicle-service-management-system-service-list-stored-cross-site-scripting-xss

Vehicle-Service-Management-System-Service-List-Stored-Cross-Site-Scripting-XSS

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-46072 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.

View Repository
13 months agoNot yet reviewed

CVE-2021-46072

Exploit Title: Vehicle Service Management System - 'Service List' Stored Cross Site Scripting (XSS)

Exploit Author: SANU P.L

CVE: CVE-2021-46072

CVSS: 4.8 MEDIUM

References:

  • https://www.plsanu.com/vehicle-service-management-system-service-list-stored-cross-site-scripting-xss
  • https://nvd.nist.gov/vuln/detail/CVE-2021-46072
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46072

Description:

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List Section in login panel.

Exploit:

  1. Login to the admin panel http://localhost/vehicle_service/admin
  2. Navigate to Service List section and click on Create New button.
  3. Inject the below payload in Service Name & Description input field.

Payload:

root@kitploit:~
 "><script>alert(document.cookie)</script>
  1. Click on Save button.
  2. Malicious javascript code triggered.

Impact:

An attacker can able to inject malicious JavaScript code in Service List Section.

Mitigation:

It is recommended to sanitize all the input fields throughout the application.

Download Tool