← volver
CVE-2023-1113

SourceCodester Simple Payroll System POST Parameter cross site scripting

CVSS 2.4 LOWEPSS 0.6%CWE-79
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 2.4EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
01 mar 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=admin of the component POST Parameter Handler. The manipulation of the argument fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222073 was assigned to this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →