PoC Index

CVE-2021-43657

MEDIUM 5.4EPSS 0.7%

A Stored Cross-site scripting (XSS) vulnerability via MAster.php in Sourcecodetester Simple Client Management System (SCMS) 1.0 allows remote attackers to inject arbitrary web script or HTML via the vulnerable input fields.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.72% chance of exploitation in the next 30 days, 51th percentile
Published
2022-12-22
Updated
2025-04-16

Proof-of-concept exploits (1)

References

Related