CVE-2023-3858: phpscriptpoint Car Listing search.php cross site scripting
A vulnerability has been found in phpscriptpoint Car Listing 1.6 and classified as problematic. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument country/state/city leads to cross site scripting. The attack can be initiated remotely. VDB-235210 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3858?
CVE-2023-3858 is classified as a problematic vulnerability due to its potential for remote exploitation.
How do I fix CVE-2023-3858?
To fix CVE-2023-3858, ensure you sanitize and validate user inputs in the /search.php file to prevent cross-site scripting.
What type of vulnerability is CVE-2023-3858?
CVE-2023-3858 is a cross-site scripting (XSS) vulnerability that can be exploited via manipulated inputs.
Can CVE-2023-3858 be exploited remotely?
Yes, CVE-2023-3858 can be exploited remotely, allowing attackers to execute malicious scripts on affected systems.
Which software is affected by CVE-2023-3858?
CVE-2023-3858 affects version 1.6 of the Phpscriptpoint Car Listing software.