CVE-2023-51802: XSS
Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the page or classmonth parameter in the /php-attendance/attendancereport component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51802?
CVE-2023-51802 is classified as a Cross Site Scripting (XSS) vulnerability, which can allow attackers to execute arbitrary code.
How do I fix CVE-2023-51802?
To fix CVE-2023-51802, sanitize and validate user input for the page or class_month parameters in the /php-attendance/attendance_report component.
Who is affected by CVE-2023-51802?
CVE-2023-51802 affects users of Simple Student Attendance System version 1.0.
What kind of attacks can CVE-2023-51802 enable?
CVE-2023-51802 can enable remote attackers to execute arbitrary script code in the context of the user's session.
Is CVE-2023-51802 exploitable without authentication?
Yes, CVE-2023-51802 can be exploited by remote attackers without the need for authentication.