CVE-2023-1988: SourceCodester Online Computer and Laptop Store cross site scripting
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/?page=maintenance/brand. The manipulation of the argument Brand Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225536.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1988?
The severity of CVE-2023-1988 is medium (4.8).
What is the affected software of CVE-2023-1988?
The affected software of CVE-2023-1988 is SourceCodester Online Computer and Laptop Store 1.0.
What is the CWE of CVE-2023-1988?
The CWE of CVE-2023-1988 is CWE-79 (Cross-site Scripting).
How can I exploit CVE-2023-1988?
Exploiting CVE-2023-1988 involves manipulating the 'Brand Name' argument in the /admin/?page=maintenance/brand page to carry out cross-site scripting attacks.
What is the fix for CVE-2023-1988?
To fix CVE-2023-1988, the software vendor should release a patch or update that addresses the cross-site scripting vulnerability in the 'Brand Name' parameter.