# Exploit Title: Multiple Stored XSS in CRUD Operation software # Date: 4/1/2021 # Exploit Author: Arnav Tripathy # Vendor Homepage: https://egavilanmedia.com # Software Link: https://egavilanmedia.com/crud-operation-with-php-mysql-bootstrap-and-dompdf/ # Version: 1.0 # Tested on: linux / Lamp Click on add new record. Simply put and so on in all parameters. Pop up should come up moment you add the record. If not , simply refresh the page, it should come up.