PT-2023-32768 · Sourcecodester · Sourcecodester Wedding Guest E-Book

·

CVE-2023-6767

·

Published

2023-12-13

·

Updated

2024-05-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Wedding Guest e-Book version 1.0
Description A vulnerability was found in SourceCodester Wedding Guest e-Book, affecting an unknown part of the file "/endpoint/add-guest.php". The manipulation of the name argument leads to cross-site scripting. It is possible to initiate the attack remotely.
Recommendations For version 1.0, consider disabling access to the "/endpoint/add-guest.php" endpoint until a patch is available. Restrict the manipulation of the name argument to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-6767

Affected Products

Sourcecodester Wedding Guest E-Book