CVE-2023-0527
PHPGurukul Online Security Guards Hiring System search-request.php cross site scripting
Record summary
CVE-2023-0527 has a selected CVSS score of 3.5 (low); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php. The manipulation of the argument searchdata with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219596.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Online Security Guards Hiring SystemBrowse PHPGurukul / Online Security Guards Hiring System | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBOnline Security Guards Hiring System 1.0 - Reflected XSSExploitDB exploitby AFFAN AHMEDNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMOnline Security Guards Hiring System - Cross-Site ScriptingCVSS 6.1
A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php.
Impact
Unauthenticated attackers can inject malicious JavaScript through the searchdata parameter in search-request.php to steal user session cookies and execute attacks.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery