First published: Wed Mar 22 2023(Updated: )
A vulnerability classified as problematic has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file /admin/reports/index.php of the component GET Parameter Handler. The manipulation of the argument date_to leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223560.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Student Study Center Desk Management System Project Student Study Center Desk Management System | =1.0 | |
Oretnom23 Student Study Center Desk Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1568 is a vulnerability found in SourceCodester Student Study Center Desk Management System 1.0, specifically in the file /admin/reports/index.php.
CVE-2023-1568 allows for cross-site scripting (XSS) attacks through manipulation of the 'date_to' argument in the component GET Parameter Handler.
CVE-2023-1568 has a severity rating of 5.4, which is considered medium.
To fix CVE-2023-1568, it is recommended to update the SourceCodester Student Study Center Desk Management System to the latest version or apply the necessary patches or fixes provided by the vendor.
CVE-2023-1568 is associated with CWE-79, which is the weakness category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').