First published: Thu Dec 07 2023(Updated: )
A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpjabbers Shuttle Booking Software | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48172 is a Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0.
The severity of CVE-2023-48172 is medium with a CVSS score of 5.4.
CVE-2023-48172 allows a remote attacker to inject JavaScript through the name, description, title, or address parameter in index.php.
The affected software for CVE-2023-48172 is Phpjabbers Shuttle Booking Software 2.0.
To fix CVE-2023-48172, users should update to a patched version of Shuttle Booking Software.