Vulnerability Details CVE-2021-40909
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.6%
CVSS Severity
CVSS v3 Score 9.6
CVSS v2 Score 6.8
Products affected by CVE-2021-40909
-
cpe:2.3:a:php_crud_without_refresh/reload_using_ajax_and_datatables_tutorial_project:php_crud_without_refresh/reload_using_ajax_and_datatables_tutorial:1.0