PT-2023-16954 · Sourcecodester · Sourcecodester Online Student Management System

·

CVE-2023-1397

·

Publicado

2023-03-14

·

Atualizado

2024-05-17

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Online Student Management System version 1.0
Description A vulnerability has been found in the SourceCodester Online Student Management System. The issue is related to an unknown function of the file profile.php, where the manipulation of the adminname argument leads to cross-site scripting. This can be exploited remotely.
Recommendations For version 1.0, consider disabling the adminname argument in the profile.php file until a patch is available. Restrict access to the profile.php file to minimize the risk of exploitation. Avoid using the adminname argument in the affected function until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-1397

Produtos afetados

Sourcecodester Online Student Management System