First published: Mon Nov 13 2023(Updated: )
Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-46020 is medium.
The affected software for CVE-2023-46020 is Code-Projects Blood Bank 1.0.
Attackers can exploit CVE-2023-46020 by running arbitrary code via the 'rename', 'remail', 'rphone', and 'rcity' parameters in updateprofile.php.
Yes, it is recommended to apply the latest patch or update provided by Code-Projects for Blood Bank 1.0 to fix CVE-2023-46020.
The Common Weakness Enumeration (CWE) associated with CVE-2023-46020 is CWE-79 (Cross-Site Scripting).