PT-2023-17254 · Sourcecodester · Sourcecodester Employee Payslip Generator

·

CVE-2023-1796

·

Published

2023-04-02

·

Updated

2024-05-17

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Employee Payslip Generator version 1.0
Description A problematic vulnerability has been found in the Create News Handler component of the SourceCodester Employee Payslip Generator. The issue is related to an unknown function of the file /classes/Master.php?f=save position. The manipulation of the name argument with malicious input, such as <script>alert(document.cookie)</script>, leads to cross-site scripting. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations For version 1.0, consider disabling the Create News Handler component or restricting access to the /classes/Master.php?f=save position file until a patch is available. Avoid using the name argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-1796

Affected Products

Sourcecodester Employee Payslip Generator