CVE-2023-0563
PHPGurukul Bank Locker Management System Assign Locker add-locker-form.php cross site scripting
Record summary
CVE-2023-0563 has a selected CVSS score of 3.5 (low); EIP currently links 1 Nuclei template.
Description
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Bank Locker Management SystemBrowse PHPGurukul / Bank Locker Management System | CVE List | 1.0 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMBank Locker Management System - Cross-Site ScriptingCVSS 4.8
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery