PT-2023-27988 · Unknown · Dairy Farm Shop Management System Using Php/Mysql

Shivam Sharma

·

Publicado

2023-09-11

·

Atualizado

2023-09-15

·

CVE-2023-41593

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dairy Farm Shop Management System Using PHP and MySQL version 1.1
Description The issue allows attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters. This enables the execution of malicious scripts, potentially leading to unauthorized access or data manipulation.
Recommendations For Dairy Farm Shop Management System Using PHP and MySQL version 1.1, consider disabling the Category and Category Field parameters until a patch is available to prevent the injection of crafted payloads. Restrict access to these parameters to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-41593

Produtos afetados

Dairy Farm Shop Management System Using Php/Mysql