First published: Thu Jul 27 2023(Updated: )
A vulnerability, which was classified as problematic, was found in GZ Scripts Availability Booking Calendar PHP 1.0. This affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler. The manipulation of the argument img leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235569 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gzscripts Availability Booking Calendar Php | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3970 is medium with a severity value of 5.4.
CVE-2023-3970 affects an unknown part of the file /index.php?controller=GzUser&action=edit&id=1 of the component Image Handler.
CVE-2023-3970 is a cross-site scripting vulnerability in GZ Scripts Availability Booking Calendar PHP 1.0.
To fix CVE-2023-3970, it is recommended to apply the latest security patch provided by the vendor.
Yes, you can find additional information about CVE-2023-3970 in the following references: [link1](https://seclists.org/fulldisclosure/2023/Jul/51), [link2](https://vuldb.com/?ctiid.235569), [link3](https://vuldb.com/?id.235569).