PT-2023-22801 · Code Projects · Agro-School Management System

Zhangwang

·

Publicado

2023-06-02

·

Atualizado

2024-05-17

·

CVE-2023-3060

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Agro-School Management System version 1.0
Description A vulnerability has been found in the code-projects Agro-School Management System, affecting the function doAddQuestion of the file btn functions.php. The manipulation of the argument Question leads to cross-site scripting. The attack can be initiated remotely.
Recommendations For version 1.0, consider disabling the doAddQuestion function until a patch is available to prevent cross-site scripting attacks. Restrict access to the btn functions.php file to minimize the risk of exploitation. Avoid using the Question argument in the affected function until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-3060

Produtos afetados

Agro-School Management System