SourceCodester Online Book Store System System Settings index.php site_settings cross site scripting
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 4.8epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
SourceCodester · Online Book Store Systempublic PoCs found — 1
cve_referencemedium.com/@hemantrajbhati5555/stored-cross-site-scripting-xss-in-system-settings-module-fa4f99ed1544unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.