CVE-2023-36346
MEDIUM NUCLEIPOS Codekop v2.0 - Reflected Cross-Site Scripting via nm_member Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-36346. PoCs published by Amirhossein Bahramizadeh. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Sales of Cashier Goods v1.0 by injecting a malicious script via the 'nm_member' parameter in the print.php endpoint. The payload is URL-encoded and sent as a GET request, triggering the XSS when the response is rendered.
Description
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parameter at print.php.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in Sales of Cashier Goods v1.0 by injecting a malicious script via the 'nm_member' parameter in the print.php endpoint. The payload is URL-encoded and sent as a GET request, triggering the XSS when the response is rendered.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N