Description
Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature that allows administrators to inject malicious scripts. Attackers can insert a payload in the Category Name field to execute arbitrary JavaScript code when the page is loaded.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Kislay Kumar
References
www.exploit-db.com/exploits/49292 (ExploitDB-49292)
xeroneit.net/ (Vendor Homepage)
xeroneit.net/portfolio/library-management-system-lms (Software Product Page)
www.vulncheck.com/...ent-system-add-book-category-stored-xss (VulnCheck Advisory: Xeroneit Library Management System 3.1 - "Add Book Category " Stored XSS)