A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addproduct.php. The manipulation of the argument prodname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231163.
References
Link | Resource |
---|---|
https://github.com/wenwochunfeng/bugReport/blob/main/XSS.md | Exploit |
https://vuldb.com/?ctiid.231163 | Third Party Advisory |
https://vuldb.com/?id.231163 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Jun 2023, 03:10
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CPE | cpe:2.3:a:performance_indicator_system_project:performance_indicator_system:1.0:*:*:*:*:*:*:* | |
References | (MISC) https://github.com/wenwochunfeng/bugReport/blob/main/XSS.md - Exploit | |
References | (MISC) https://vuldb.com/?id.231163 - Third Party Advisory | |
References | (MISC) https://vuldb.com/?ctiid.231163 - Third Party Advisory |
09 Jun 2023, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-09 13:15
Updated : 2024-05-17 02:27
NVD link : CVE-2023-3183
Mitre link : CVE-2023-3183
CVE.ORG link : CVE-2023-3183
JSON object : View
Products Affected
performance_indicator_system_project
- performance_indicator_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')