Record summary

CVE-2023-29623 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryMEDIUMPurchase Order Management v1.0 - Cross Site Scripting (Reflected)CVSS 6.1

Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-79
Authorstheamanrawat
Template tagscve2023cvexsspurchase-order-management-systempurchase_order_management_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:purchase_order_management_project:purchase_order_management:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3