packetstormsecurity.comrelated
http://packetstormsecurity.com/files/172908/Sales-Tracker-Management-System-1.0-HTML-Injection.html CVE-2023-3184
LOW
SourceCodester Sales Tracker Management System cross site scripting
Record summary
CVE-2023-3184 has a selected CVSS score of 2.4 (low); EIP currently links 1 catalogued exploit.
Description
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231164.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Sales Tracker Management SystemBrowse SourceCodester / Sales Tracker Management System | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSales Tracker Management System v1.0 - Multiple VulnerabilitiesExploitDB exploitby AFFAN AHMEDNot analyzed1 file
References
5github.comexploit
https://github.com/ctflearner/Vulnerability/blob/main/Sales_Tracker_Management_System/stms.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-3184 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.231164 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.231164