Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gist.github.com/mayank-s16/19b22b3b356646dce2639a9400f3f7d9 | third party advisory exploit |
https://www.campcodes.com/projects/php/simple-bakery-shop-management-system/ | product third party advisory |