First published: Mon Jul 10 2023(Updated: )
Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Online Fire Reporting System Project Online Fire Reporting System | =1.2 | |
PHPGurukul Online Fire Reporting System | =1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36940 is a Cross Site Scripting (XSS) vulnerability in the PHPGurukul Online Fire Reporting System v.1.2
CVE-2023-36940 allows attackers to execute arbitrary code through a crafted payload injected into the search field.
CVE-2023-36940 has a severity level of medium (4).
To fix CVE-2023-36940, it is recommended to apply the latest patch or update provided by the Online Fire Reporting System project.
You can find more information about CVE-2023-36940 on the following links: - [Medium article](https://medium.com/@ridheshgohil1092/cve-2023-36940-xss-on-online-fire-reporting-system-v-1-2-1d3fa170e4d6) - [Packet Storm Security](https://packetstormsecurity.com)