First published: Sat Oct 14 2023(Updated: )
A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/?page=bike of the component Bike List. The manipulation of the argument Model with the input "><script>confirm (document.cookie)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-242170 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 Online Motorcycle \(bike\) Rental System | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5585 is medium with a CVSS score of 6.1.
The component affected by CVE-2023-5585 is the Bike List, specifically the /admin/?page=bike file.
CVE-2023-5585 performs manipulation of the argument Model with a payload containing a script to confirm something.
CVE-2023-5585 affects version 1.0 of SourceCodester Online Motorcycle Rental System.
The Common Weakness Enumeration (CWE) associated with CVE-2023-5585 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').