Stored XSS Vulnerability in PHPGurukul Daily Expense Tracker System
CVE-2020-10107
5.4MEDIUM
What is CVE-2020-10107?
The PHPGurukul Daily Expense Tracker System 1.0 contains a stored XSS vulnerability, primarily affecting the parameters ExpenseItem and ExpenseCost within manage-expense.php. This flaw allows attackers to inject malicious scripts into the web application, which can subsequently execute in the context of a user's browser, potentially compromising sensitive data and user sessions.