Medium severity5.4NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026
CVE-2021-29387
CVE-2021-29387
Description
Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:equipment_inventory_system_project:equipment_inventory_system:1.0:*:*:*:*:*:*:*
- Sourcecodester/Equipment Inventory Systemdescription
- Range: 1.0
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/49722nvdExploitThird Party AdvisoryVDB Entry
- www.sourcecodester.com/php/11327/equipment-inventory.htmlnvdProduct
News mentions
0No linked articles in our index yet.