CVE-2023-41575: XSS
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-41575?
CVE-2023-41575 is a vulnerability that allows attackers to execute arbitrary web scripts or HTML through multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2.
How severe is CVE-2023-41575?
CVE-2023-41575 has a severity rating of medium, with a CVSS score of 5.4.
How can an attacker exploit CVE-2023-41575?
Attackers can exploit CVE-2023-41575 by injecting a crafted payload into the Full Name, Message, or Address parameters in /bbdms/sign-up.php.
What software is affected by CVE-2023-41575?
Blood Bank & Donor Management v2.2 is affected by CVE-2023-41575.
Is there a fix available for CVE-2023-41575?
At the moment, there is no known fix for CVE-2023-41575. It is recommended to apply any patches or updates provided by the software vendor.