Critical severity9.6NVD Advisory· Published Jan 24, 2022· Updated Jun 17, 2026
CVE-2021-40909
CVE-2021-40909
Description
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- PHP Crud Without Refresh\/reload Using Ajax And Datatables Tutorial Project/PHP Crud Without Refresh\/reload Using Ajax And Datatables Tutorialcpe:2.3:a:php_crud_without_refresh\/reload_using_ajax_and_datatables_tutorial_project:php_crud_without_refresh\/reload_using_ajax_and_datatables_tutorial:1.0:*:*:*:*:*:*:*
- sourcecodester/PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorialdescription
Patches
Vulnerability mechanics
References
1- github.com/nu11secur1ty/CVE-nu11secur1ty/tree/main/vendors/oretnom23/CVE-nu11-10-09102021nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.