CVE-2023-36159: XSS
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36159?
The severity of CVE-2023-36159 is medium with a severity value of 6.1.
How does the Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 work?
The vulnerability allows remote attackers to run arbitrary code by injecting it into the First Name, Middle Name, and Last Name fields on the Create User page.
Which software version is affected by CVE-2023-36159?
Version 1.0 of the Oretnom23 Lost and Found Information System is affected by CVE-2023-36159.
Is there a fix available for this vulnerability?
It is recommended to update to a patched version or apply a security fix provided by the software vendor to mitigate the vulnerability.
Where can I find more information about CVE-2023-36159?
More information about CVE-2023-36159 can be found at the following references: [http://lost.com, https://www.sourcecodester.com/php/16525/lost-and-found-information-system-using-php-and-mysql-db-source-code-free-download.html, https://cyberredteam.tech/posts/cve-2023-36159/].