PT-2023-23405 · Sourcecodester · Sourcecodester Insurance Management System
Wengao
·
Publicado
2023-06-08
·
Atualizado
2024-05-17
·
CVE-2023-3165
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Life Insurance Management System version 1.0
Description
A vulnerability was found in the file insertNominee.php of the component POST Parameter Handler. The manipulation of the
nominee id argument leads to cross site scripting. The attack can be launched remotely.Recommendations
For version 1.0, consider disabling the
insertNominee.php file or restricting access to the POST Parameter Handler component until a patch is available. Avoid using the nominee id argument in the affected API endpoint until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sourcecodester Insurance Management System