CVE-2023-3382

A vulnerability, which was classified as problematic, has been found in SourceCodester Game Result Matrix System 1.0. Affected by this issue is some unknown functionality of the file /dipam/save-delegates.php of the component GET Parameter Handler. The manipulation of the argument del_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-232238 is the identifier assigned to this vulnerability.
References
Link Resource
https://github.com/M9KJ-TEAM/CVEReport/blob/main/XSS3.md Exploit
https://vuldb.com/?ctiid.232238 Permissions Required Third Party Advisory
https://vuldb.com/?id.232238 Permissions Required Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:game_result_matrix_system_project:game_result_matrix_system:1.0:*:*:*:*:*:*:*

History

28 Jun 2023, 07:24

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-23 10:15

Updated : 2024-05-17 02:27


NVD link : CVE-2023-3382

Mitre link : CVE-2023-3382

CVE.ORG link : CVE-2023-3382


JSON object : View

Products Affected

game_result_matrix_system_project

  • game_result_matrix_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')