CVE-2023-3886: Campcodes Beauty Salon Management System invoice.php cross site scripting
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/invoice.php. The manipulation of the argument invid leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235248.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3886?
The severity of CVE-2023-3886 is medium with a CVSS score of 6.1.
What is the affected software for CVE-2023-3886?
The affected software for CVE-2023-3886 is Campcodes Beauty Salon Management System 1.0.
What is the CWE number for CVE-2023-3886?
The CWE number for CVE-2023-3886 is 79.
How can I exploit CVE-2023-3886?
CVE-2023-3886 can be exploited by manipulating the 'inv_id' argument in the /admin/invoice.php file to perform cross site scripting attacks.
Is it possible to launch the attack remotely for CVE-2023-3886?
Yes, it is possible to launch the attack remotely for CVE-2023-3886.