CVE-2023-46020: XSS
Published Nov 13, 2023
·Updated
Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.
Affected Software
1 affected component
Code-projects Blood Bank=1.0
Event History
Nov 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46020?
The severity of CVE-2023-46020 is medium.
2
What is the affected software for CVE-2023-46020?
The affected software for CVE-2023-46020 is Code-Projects Blood Bank 1.0.
3
How can attackers exploit CVE-2023-46020?
Attackers can exploit CVE-2023-46020 by running arbitrary code via the 'rename', 'remail', 'rphone', and 'rcity' parameters in updateprofile.php.
4
Is there a fix available for CVE-2023-46020?
Yes, it is recommended to apply the latest patch or update provided by Code-Projects for Blood Bank 1.0 to fix CVE-2023-46020.
5
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-46020?
The Common Weakness Enumeration (CWE) associated with CVE-2023-46020 is CWE-79 (Cross-Site Scripting).