First published: Fri Sep 29 2023(Updated: )
A vulnerability, which was classified as problematic, has been found in SourceCodester Expense Tracker App v1. Affected by this issue is some unknown functionality of the file add_category.php of the component Category Handler. The manipulation of the argument category_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-240914 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Expense Tracker | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-5286.
The severity of CVE-2023-5286 is medium with a CVSS score of 5.4.
SourceCodester Expense Tracker App v1 is affected by CVE-2023-5286.
CVE-2023-5286 is classified as CWE-79, which is Cross-Site Scripting (XSS).
To fix CVE-2023-5286, it is recommended to apply the latest patch or update provided by the vendor.