First published: Thu Feb 29 2024(Updated: )
Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the page or class_month parameter in the /php-attendance/attendance_report component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sourcecodester Simple Student Attendance System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51802 is classified as a Cross Site Scripting (XSS) vulnerability, which can allow attackers to execute arbitrary code.
To fix CVE-2023-51802, sanitize and validate user input for the page or class_month parameters in the /php-attendance/attendance_report component.
CVE-2023-51802 affects users of Simple Student Attendance System version 1.0.
CVE-2023-51802 can enable remote attackers to execute arbitrary script code in the context of the user's session.
Yes, CVE-2023-51802 can be exploited by remote attackers without the need for authentication.