github.comexploit
https://github.com/tht1997/CVE_2023/blob/main/Lost%20and%20Found%20Information%20System/CVE-2023-2671.md CVE-2023-2671
LOW
SourceCodester Lost and Found Information System Contact Form cross site scripting
Record summary
CVE-2023-2671 has a selected CVSS score of 3.5 (low).
Description
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file classes/Master.php?f=save_inquiry of the component Contact Form. The manipulation of the argument fullname/contact/message leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-228887.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 22, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Lost and Found Information SystemBrowse SourceCodester / Lost and Found Information System | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2671 vuldb.comsignature
https://vuldb.com/?ctiid.228887 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.228887