CVE-2023-31935: XSS
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31935?
CVE-2023-31935 is classified as a Cross Site Scripting (XSS) vulnerability which is considered high risk due to its potential for data exposure.
How do I fix CVE-2023-31935?
To fix CVE-2023-31935, validate and sanitize all user inputs, especially the 'email' parameter in admin-profile.php.
Which versions of Rail Pass Management System are affected by CVE-2023-31935?
CVE-2023-31935 affects version 1.0 of the Rail Pass Management System.
What types of attacks can CVE-2023-31935 facilitate?
CVE-2023-31935 can facilitate attacks that enable remote attackers to execute malicious scripts in the context of a user's browser.
Who is affected by CVE-2023-31935?
Any user of the Rail Pass Management System v.1.0, particularly administrators, may be affected by CVE-2023-31935.