Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://www.sourcecodester.com/php/15273/online-market-place-site-phpoop-free-source-code.html | product |
https://packetstormsecurity.com/files/168250/omps10-xss.txt | exploit vdb entry third party advisory |