CVE-2023-23021

MEDIUM

oretnom23 POS Point of Sale System 1.0 - Stored Cross-Site Scripting via Main.php Inputs

Title source: llm
STIX 2.1

Description

Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0022
EPSS Percentile 44.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
oretnom23/pos_-_point_of_sale_system 1.0
Published May 01, 2024
Tracked Since Feb 18, 2026