First published: Thu Aug 03 2023(Updated: )
Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Toll Tax Management System | =1.0 | |
Toll Tax Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36158 is medium.
The remote attackers can run arbitrary code by exploiting the Cross Site Scripting (XSS) vulnerability in the First Name and Last Name fields on the My Account page.
To fix the XSS vulnerability, update sourcecodester Toll Tax Management System to a version that addresses the vulnerability.
Yes, there are reference materials available for CVE-2023-36158. The references include: [http://toll.com](http://toll.com), [https://github.com/unknown00759/CVE-2023-36158/blob/main/CVE-2023-36158.md](https://github.com/unknown00759/CVE-2023-36158/blob/main/CVE-2023-36158.md), and [https://cyberredteam.tech/posts/cve-2023-36158/](https://cyberredteam.tech/posts/cve-2023-36158/).
The CWE ID associated with CVE-2023-36158 is 79.