{"id":"CVE-2021-21260","details":"Online Invoicing System (OIS) is open source software which is a lean invoicing system for small businesses, consultants and freelancers created using AppGini. In OIS version 4.0 there is a stored XSS which can enables an attacker takeover of the admin account through a payload that extracts a csrf token and sends a request to change password. It has been found that Item description is reflected without sanitization in app/items_view.php which enables the malicious scenario.","modified":"2026-04-10T04:29:34.304017Z","published":"2021-01-22T18:15:12.610Z","related":["GHSA-rm79-5596-r7q4"],"references":[{"type":"ADVISORY","url":"https://github.com/bigprof-software/online-invoicing-system/releases/tag/4.2"},{"type":"EVIDENCE","url":"https://github.com/bigprof-software/online-invoicing-system/security/advisories/GHSA-rm79-5596-r7q4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bigprof-software/online-invoicing-system","events":[{"introduced":"0"},{"last_affected":"18522835aa2b23c5376bc1c68ef727f41f334f79"},{"fixed":"4e4d8d0a4017f0b3d56b281b47223785dcb7ffec"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"4.0"}]}}],"versions":["2.3","2.4","2.5","2.6","2.9","3.0","3.1","4.0","4.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21260.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}