First published: Thu Nov 30 2023(Updated: )
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add-phlebotomist.php. The manipulation of the argument empid/fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246445 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-6442 is medium, with a severity value of 5.4.
The affected software of CVE-2023-6442 is PHPGurukul Nipah Virus Testing Management System version 1.0.
CVE-2023-6442 is a cross-site scripting (XSS) vulnerability in the 'add-phlebotomist.php' file of PHPGurukul Nipah Virus Testing Management System.
The Common Weakness Enumeration (CWE) of CVE-2023-6442 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
CVE-2023-6442 can be exploited by manipulating the 'empid/fullname' argument in the 'add-phlebotomist.php' file to execute cross-site scripting attacks.