First published: Sat Jan 28 2023(Updated: )
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 | ||
Bank Locker Management System Project Bank Locker Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0563 is medium with a CVSS score of 4.8.
CVE-2023-0563 affects the PHPGurukul Bank Locker Management System version 1.0.
CVE-2023-0563 is classified as CWE-79 (Cross-Site Scripting).
There is currently no known fix available for CVE-2023-0563. It is recommended to follow best security practices and implement appropriate mitigations.
More information about CVE-2023-0563 can be found at the following references: [1](https://vuldb.com/?id.219717) [2](https://vuldb.com/?ctiid.219717) [3](https://github.com/ctflearner/Vulnerability/blob/main/Bank_Locker_Management_System/BLMS_XSS_IN_ADMIN_BROWSER.md)