First published: Fri May 12 2023(Updated: )
A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file admin/. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-228883.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Lost And Found Information System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2667 is medium with a CVSS score of 6.1.
CVE-2023-2667 affects SourceCodester Lost and Found Information System 1.0 by allowing remote attackers to perform cross-site scripting attacks through the manipulation of the 'page' argument.
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
An attacker can exploit CVE-2023-2667 by manipulating the 'page' argument to inject and execute malicious scripts on the target system, potentially stealing sensitive information or compromising user sessions.
To fix CVE-2023-2667, it is recommended to apply the latest security updates or patches provided by the vendor, or implement appropriate input validation and output encoding to mitigate the risk of cross-site scripting attacks.