Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code via signup form in the Name and Phone number field.
References
| Link | Resource |
|---|---|
| https://github.com/MartDevelopers-Inc/Order_Processing_MIS | Third Party Advisory |
| https://medium.com/%40mayhem7999/cve-2021-43439-d04781bca6ce |
Configurations
History
07 Nov 2023, 03:39
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
Information
Published : 2021-12-20 20:15
Updated : 2023-11-07 03:39
NVD link : CVE-2021-43440
Mitre link : CVE-2021-43440
JSON object : View
Products Affected
iorder_project
- iorder
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
