Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.
References
Link | Resource |
---|---|
https://github.com/ASR511-OO7/CVE-2023-42307/blob/main/CVE-6 | Exploit Third Party Advisory |
https://github.com/ASR511-OO7/CVE-2023-42307/blob/main/CVE-6 | Exploit Third Party Advisory |
Configurations
History
22 Jan 2025, 14:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ASR511-OO7/CVE-2023-42307/blob/main/CVE-6 - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
First Time |
Code-projects
Code-projects exam Form Submission |
|
CWE | CWE-79 | |
CPE | cpe:2.3:a:code-projects:exam_form_submission:1.0:*:*:*:*:*:*:* |
21 Nov 2024, 08:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ASR511-OO7/CVE-2023-42307/blob/main/CVE-6 - |
13 Mar 2024, 12:33
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
12 Mar 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-12 21:15
Updated : 2025-01-22 14:54
NVD link : CVE-2023-42307
Mitre link : CVE-2023-42307
CVE.ORG link : CVE-2023-42307
JSON object : View
Products Affected
code-projects
- exam_form_submission
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')