First published: Thu Sep 28 2023(Updated: )
Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.
Credit: help@fluidattacks.com help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Online Movie Ticket Booking System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability in CVE-2023-44173 is an authenticated Reflected Cross-Site Scripting (XSS) vulnerability.
The vulnerability allows an attacker to inject malicious scripts into the website, which can lead to the execution of unauthorized actions or stealing of user information.
The severity of CVE-2023-44173 is medium, with a severity value of 5.4.
To fix the vulnerability, it is recommended to implement input validation and output encoding to prevent the injection of malicious scripts.
You can find more information about CVE-2023-44173 at the following references: [Advisory by Fluid Attacks](https://fluidattacks.com/advisories/harrison) and [Projectworlds website](https://projectworlds.in/).