Exploits / Vulnerability Discovered : 2021-02-25 |
Type : webapps |
Platform : php
This exploit / vulnerability Vehicle parking management system 1.0 catename persistent crosssite scripting (xss) is for educational purposes only and if it is used you will do on your own risk!
*Steps to Reproduce:*
1) Login with Admin Credentials and click on the '*Manage category*' button.
2) Click on the '*Add Categories*' button.
3) Now add the 'Ba1man' in the input field of '*Category*' and intercept it with Burp Suite.
4) Now add the following payload input field of *Category *as a parameter name is *catename*