Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Vehicle-Service-Management-System-Settings-Stored-Cross-Site-Scripting-XSS — CVE-2021-46074 - A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings Section in login panel. | Kitploit
Tools/GitHubGitHub/sanupl/vehicle-service-management-system-settings-stored-cross-site-scripting-xss
Web Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubsanupl/vehicle-service-management-system-settings-stored-cross-site-scripting-xss

Vehicle-Service-Management-System-Settings-Stored-Cross-Site-Scripting-XSS

CVE-2021-46074 - A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings Section in login panel.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
3 months agoNot yet reviewed

CVE-2021-46074

Exploit Title: Vehicle Service Management System - 'Settings' Stored Cross Site Scripting (XSS)

Exploit Author: SANU P.L

CVE: CVE-2021-46074

CVSS: 4.8 MEDIUM

References:

  • https://www.plsanu.com/vehicle-service-management-system-settings-stored-cross-site-scripting-xss
  • https://nvd.nist.gov/vuln/detail/CVE-2021-46074
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46074

Description:

A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings Section in login panel.

Exploit:

  1. Login to the admin panel http://localhost/vehicle_service/admin
  2. Navigate to Settings section http://localhost/vehicle_service/admin/?page=system_info
  3. Inject the below payload in System Name, System Short Name & About Us input field.

Payload:

root@kitploit:~
 "><script>alert(document.cookie)</script>
  1. Click on update button.
  2. Malicious javascript code triggered.

Impact:

An attacker can able to inject malicious JavaScript code in Settings Section.

Mitigation:

It is recommended to sanitize all the input fields throughout the application.

Download Tool