Description
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.
References
https://gist.github.com/enferas/649f39c955ce2816ba1abae620e749c7
ExploitThird Party Advisory
https://github.com/ronknight/InventorySystem/issues/23
ExploitIssue TrackingThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2023-01-20T19:15:18.117
1 year agoLast modified
2023-01-28T02:47:30.483
1 year ago