kr1shna4garwal.github.ioexploit
https://kr1shna4garwal.github.io/posts/cve-poc-2023 CVE-2023-3311
LOW
PuneethReddyHC online-shopping-system-advanced addsuppliers.php cross site scripting
Record summary
CVE-2023-3311 has a selected CVSS score of 2.4 (low).
Description
A vulnerability, which was classified as problematic, was found in PuneethReddyHC online-shopping-system-advanced 1.0. This affects an unknown part of the file addsuppliers.php. The manipulation of the argument First name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231807.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
online-shopping-system-advancedBrowse PuneethReddyHC / online-shopping-system-advanced | CVE List | 1.0 | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-3311 vuldb.comsignaturepermissions required
https://vuldb.com/?ctiid.231807 vuldb.comvdb entryTechnical description
https://vuldb.com/?id.231807