Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Vehicle-Service-Management-System-Service-Requests-Stored-Cross-Site-Scripting-XSS — CVE-2021-46070 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel. | Kitploit
Tools/GitHubGitHub/sanupl/vehicle-service-management-system-service-requests-stored-cross-site-scripting-xss
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubsanupl/vehicle-service-management-system-service-requests-stored-cross-site-scripting-xss

Vehicle-Service-Management-System-Service-Requests-Stored-Cross-Site-Scripting-XSS

CVE-2021-46070 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
3 months agoNot yet reviewed

CVE-2021-46070

Exploit Title: Vehicle Service Management System - 'Service Requests' Stored Cross Site Scripting (XSS)

Exploit Author: SANU P.L

CVE: CVE-2021-46070

CVSS: 4.8 MEDIUM

References:

  • https://www.plsanu.com/vehicle-service-management-system-service-requests-stored-cross-site-scripting-xss
  • https://nvd.nist.gov/vuln/detail/CVE-2021-46070
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46070

Description:

A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Requests Section in login panel.

Exploit:

  1. Login to the admin panel http://localhost/vehicle_service/admin
  2. Navigate to Service Requests section and click on Create New button.
  3. Inject the below payload in Owner Contact, Address, Vehicle Name, Vehicle Registration Number & Vehicle Model input field.

Payload:

root@kitploit:~
 "><script>alert(document.cookie)</script>
  1. Click on Save Request button.
  2. Malicious javascript code triggered.
  3. Navigate to Report section.
  4. Malicious javascript code triggered.

Impact:

An attacker can able to inject malicious JavaScript code in Service Requests Section.

Mitigation:

It is recommended to sanitize all the input fields throughout the application.

Download Tool