First published: Wed May 01 2024(Updated: )
Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows attackers to execute arbitrary code via the code, title, from_date and to_date inputs in file Main.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Employees Payroll Management System | =1.0 | |
Sourcecodester Employee's Payroll Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23022 is a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2023-23022, validate and sanitize user inputs in the affected inputs of the Main.php file.
The affected version for CVE-2023-23022 is 1.0 of the Oretnom23 Employees Payroll Management System.
CVE-2023-23022 exploits the code, title, from_date, and to_date inputs in the Main.php file.
The vendor for CVE-2023-23022 is Oretnom23, associated with the Employees Payroll Management System.