
Sourcecodester Toll Tax Management System 1.0 の manage_recipient.php におけるクロスサイトスクリプティング(XSS)の脆弱性により、リモートの認証済みユーザーが "owner" 入力フィールドを介して任意のWebスクリプトを注入することが可能です。
Sourcecodester Toll Tax Management System 1.0 の manage_recipient.php におけるクロスサイトスクリプティング (XSS) の脆弱性により、リモートの認証済みユーザーが "owner" 入力フィールドを介して任意のウェブスクリプトを注入できる可能性があります。
クロスサイトスクリプティング (XSS)
Sourcecodester
https://www.sourcecodester.com/php/15304/toll-tax-management-system-phpoop-free-source-code.html - 1.0
sourcecodester Toll Tax Management System 1.0 のクロスサイトスクリプティング (XSS) の脆弱性により、リモートの攻撃者が manage_recipient ページの owner 入力フィールドを介して任意のコードを実行できる可能性があります。
"<svg onload=alert(document.cookie)>" を注入し、残りのフォーム詳細を入力して「save」ボタンをクリックします。