/CVE-2022-3949

XSS in Simple Cashiering System

CVE-2022-3949

XSS in Simple Cashiering System

Simple Cashiering System is vulnerable to Cross Site Scripting (XSS) - a malicious actor can change the fullname of a compromised user to a XSS Payload and whenever a admin visits the user-tab or the sales tab (and looks into sales made by the malicious actor) the payload is triggered. This can lead to session takeover because the cookie does not have an HttpOnly Flag.

How-to Reproduce:

step1

step2