CVE-2023-23021

Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oretnom23:pos_-_point_of_sale_system:1.0:*:*:*:*:*:*:*

History

21 Feb 2025, 18:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Oretnom23 pos - Point Of Sale System
Oretnom23
CWE CWE-79
CPE cpe:2.3:a:oretnom23:pos_-_point_of_sale_system:1.0:*:*:*:*:*:*:*
References () https://gist.github.com/enferas/fe381bcc4a020f22cec31cb00e73f43c - () https://gist.github.com/enferas/fe381bcc4a020f22cec31cb00e73f43c - Exploit, Third Party Advisory

21 Nov 2024, 07:45

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Cross Site Scripting (XSS) en sourcecodester oretnom23 pos point sale system 1.0, permite a atacantes ejecutar código arbitrario a través de las entradas de código, nombre y descripción en el archivo Main.php.
References () https://gist.github.com/enferas/fe381bcc4a020f22cec31cb00e73f43c - () https://gist.github.com/enferas/fe381bcc4a020f22cec31cb00e73f43c -

01 May 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 19:15

Updated : 2025-03-27 21:15


NVD link : CVE-2023-23021

Mitre link : CVE-2023-23021

CVE.ORG link : CVE-2023-23021


JSON object : View

Products Affected

oretnom23

  • pos_-_point_of_sale_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')