Record summary

CVE-2023-0527 has a selected CVSS score of 3.5 (low); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php. The manipulation of the argument searchdata with the input "><script>alert(document.domain)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-219596.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBOnline Security Guards Hiring System 1.0 - Reflected XSSExploitDB exploitby AFFAN AHMEDNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMOnline Security Guards Hiring System - Cross-Site ScriptingCVSS 6.1

A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php.

Impact

Unauthenticated attackers can inject malicious JavaScript through the searchdata parameter in search-request.php to steal user session cookies and execute attacks.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsHarsh
Template tagscve2023cvepacketstormosghsxssonline_security_guards_hiring_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:online_security_guards_hiring_system_project:online_security_guards_hiring_system:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5