← volver
CVE-2023-1006

SourceCodester Medical Certificate Generator App New Record cross site scripting

CVSS 3.5 LOWEPSS 0.3%CWE-79
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 3.5EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
24 feb 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been classified as problematic. This affects an unknown part of the component New Record Handler. The manipulation of the argument Firstname/Middlename/Lastname/Suffix/Nationality/Doctor Fullname/Doctor Suffix with the input "><script>prompt(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-221739.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N