
CVE-2021-46070 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel.
A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel.
"><script>alert(document.cookie)</script>
An attacker can able to inject malicious JavaScript code in Service Requests Section.
It is recommended to sanitize all the input fields throughout the application.