CVE-2023-6442: PHPGurukul Nipah Virus Testing Management System add-phlebotomist.php cross site scripting
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add-phlebotomist.php. The manipulation of the argument empid/fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246445 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6442?
The severity of CVE-2023-6442 is medium, with a severity value of 5.4.
What is the affected software of CVE-2023-6442?
The affected software of CVE-2023-6442 is PHPGurukul Nipah Virus Testing Management System version 1.0.
What is the vulnerability description of CVE-2023-6442?
CVE-2023-6442 is a cross-site scripting (XSS) vulnerability in the 'add-phlebotomist.php' file of PHPGurukul Nipah Virus Testing Management System.
What is the CWE of CVE-2023-6442?
The Common Weakness Enumeration (CWE) of CVE-2023-6442 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
How can CVE-2023-6442 be exploited?
CVE-2023-6442 can be exploited by manipulating the 'empid/fullname' argument in the 'add-phlebotomist.php' file to execute cross-site scripting attacks.