Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0 there is a stored XSS which can enables an attacker takeover of the admin account through a payload that extracts a csrf token and sends a request to change password. It has been found that Item description is reflected without sanitization in app/items_view.php which enables the malicious scenario.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-8641 Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0 there is a stored XSS which can enables an attacker takeover of the admin account through a payload that extracts a csrf token and sends a request to change password. It has been found that Item description is reflected without sanitization in app/items_view.php which enables the malicious scenario.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-03T18:09:15.041Z

Reserved: 2020-12-22T00:00:00

Link: CVE-2021-21260

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-22T18:15:12.610

Modified: 2024-11-21T05:47:52.923

Link: CVE-2021-21260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses