First published: Tue Jul 25 2023(Updated: )
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/invoice.php. The manipulation of the argument inv_id leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235248.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Campcodes Beauty Salon Management System | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3886 is medium with a CVSS score of 6.1.
The affected software for CVE-2023-3886 is Campcodes Beauty Salon Management System 1.0.
The CWE number for CVE-2023-3886 is 79.
CVE-2023-3886 can be exploited by manipulating the 'inv_id' argument in the /admin/invoice.php file to perform cross site scripting attacks.
Yes, it is possible to launch the attack remotely for CVE-2023-3886.