CVE-2023-27225: XSS
Published Jul 6, 2023
·Updated
A cross-site scripting (XSS) vulnerability in User Registration & Login and User Management System with Admin Panel v3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the first and last name field.
Affected Software
1 affected component
User Registration \& Login And User Management System With Admin Panel Project User Registration \& Login And User Management System With Admin Panel=3.0
Event History
Jul 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-27225?
CVE-2023-27225 is classified as a cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2023-27225?
To fix CVE-2023-27225, validate and sanitize user input in the first and last name fields to prevent script injection.
3
Which versions of the User Registration & Login and User Management System are affected by CVE-2023-27225?
CVE-2023-27225 affects version 3.0 of the User Registration & Login and User Management System.
4
What types of attacks can be executed via CVE-2023-27225?
CVE-2023-27225 allows attackers to execute arbitrary web scripts or HTML on affected systems.
5
Who is the vendor for the affected software related to CVE-2023-27225?
The vendor for the affected software related to CVE-2023-27225 is PHPGurukul.