First published: Thu Aug 03 2023(Updated: )
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Lost And Found Information System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36159 is medium with a severity value of 6.1.
The vulnerability allows remote attackers to run arbitrary code by injecting it into the First Name, Middle Name, and Last Name fields on the Create User page.
Version 1.0 of the Oretnom23 Lost and Found Information System is affected by CVE-2023-36159.
It is recommended to update to a patched version or apply a security fix provided by the software vendor to mitigate the vulnerability.
More information about CVE-2023-36159 can be found at the following references: [http://lost.com, https://www.sourcecodester.com/php/16525/lost-and-found-information-system-using-php-and-mysql-db-source-code-free-download.html, https://cyberredteam.tech/posts/cve-2023-36159/].