PT-2023-13787 · Unknown · Intern Record System

H4Md153V63N

·

Publicado

2023-02-18

·

Atualizado

2025-03-17

·

CVE-2022-40348

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Intern Record System version 1.0
Description The issue is a Cross Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code. This is achieved through the /intern/controller.php endpoint, specifically by manipulating the name and email parameters.
Recommendations For Intern Record System version 1.0, consider validating and sanitizing user input for the name and email parameters in the /intern/controller.php endpoint to prevent XSS attacks. As a temporary workaround, restrict access to the /intern/controller.php endpoint until a patch is available.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-40348

Produtos afetados

Intern Record System