Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php via vulnerable field 'Budget Title'.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Budget Management System Project | Budget Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/49723Third Party AdvisoryVDB Entry
- https://www.sourcecodester.com/php/14403/budget-management-system.htmlProduct
- https://www.exploit-db.com/exploits/49723Third Party AdvisoryVDB Entry
- https://www.sourcecodester.com/php/14403/budget-management-system.htmlProduct
FAQ
What is CVE-2021-29388?
CVE-2021-29388 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php via vulnerable field 'Budget Ti...
How severe is CVE-2021-29388?
CVE-2021-29388 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29388?
Check the references section above for vendor advisories and patch information. Affected products include: Budget Management System Project Budget Management System.