Revenue Collection System 1.0 Cross Site Scripting / Authentication Bypass
Posted by deepcore on November 17, 2022 – 2:01 pm
Revenue Collection System version 1.0 suffers from a persistent cross site scripting vulnerability allowing an authenticated client user to add an administrative user account to the application then log in as the newly created admin.
Post a reply
You must be logged in to post a comment.