CVE-2023-7057: code-projects Faculty Management System yearlevel.php cross site scripting
A vulnerability, which was classified as problematic, has been found in code-projects Faculty Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/pages/yearlevel.php. The manipulation of the argument Year Level/Section leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-248744.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7057?
CVE-2023-7057 has been classified as problematic due to its impact on cross-site scripting vulnerabilities.
How do I fix CVE-2023-7057?
To fix CVE-2023-7057, input validation should be implemented to sanitize user inputs in the Year Level/Section argument.
What software is affected by CVE-2023-7057?
CVE-2023-7057 affects the Faculty Management System version 1.0 developed by Carmelo Garcia.
What type of vulnerability is CVE-2023-7057?
CVE-2023-7057 is identified as a cross-site scripting (XSS) vulnerability.
What component of the software is vulnerable in CVE-2023-7057?
The vulnerability in CVE-2023-7057 is found in the file /admin/pages/yearlevel.php.