CVE-2023-0732: SourceCodester Online Eyewear Shop POST Request Users.php registration cross site scripting
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST Request Handler. The manipulation of the argument firstname/middlename/lastname/email/contact leads to cross site scripting. The attack can be launched remotely. The identifier VDB-220369 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0732.
What is the severity of CVE-2023-0732?
The severity of CVE-2023-0732 is medium with a CVSS score of 6.1.
What is the affected software?
The affected software is SourceCodester Online Eyewear Shop 1.0.
What is the description of CVE-2023-0732 vulnerability?
CVE-2023-0732 is a cross-site scripting vulnerability in the registration function of the oews/classes/Users.php file of SourceCodester Online Eyewear Shop 1.0, which allows attackers to manipulate user-input fields.
How can I fix CVE-2023-0732?
To fix CVE-2023-0732, it is recommended to update to a patched version of SourceCodester Online Eyewear Shop.