First published: Wed Dec 13 2023(Updated: )
A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /accounts_con/register_account. The manipulation of the argument Username with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247910 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6774 is classified as problematic due to its potential impact on vulnerable systems.
To fix CVE-2023-6774, it's recommended to sanitize user inputs and ensure proper validation for the Username argument.
CVE-2023-6774 affects the CodeAstro POS and Inventory Management System version 1.0.
CVE-2023-6774 is an injection vulnerability that allows for potential script manipulation.
Yes, CVE-2023-6774 can be exploited by manipulating the Username input to execute unauthorized scripts.