CampCodes DepEd Equipment Inventory System
cpe:2.3:a:campcodes:deped_equipment_inventory_system:*:*:*:*:*:*:*
- 1.0
A stored cross-site scripting vulnerability has been identified in CampCodes DepEd Equipment Inventory System version 1.0. This issue arises in the add employee feature, specifically within the data parameter of the add_employee.php file. The vulnerability allows attackers to inject malicious JavaScript, which is executed in the browsers of users viewing the affected employee data. This could lead to session hijacking, data theft, or other malicious activities.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the data.
To reproduce this vulnerability, inject a script into the 'data' parameter when adding a new employee through the 'add_employee.php' page. Once the employee is saved, the injected script will execute when the employee data is viewed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.