PT-2023-28828 · Unknown · Service Provider Management System

Oretnom23

·

Publicado

2023-09-25

·

Atualizado

2023-09-25

·

CVE-2023-43456

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Service Provider Management System version 1.0
Description A Cross Site Scripting issue allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename, and lastname parameters in the "/php-spms/admin/?page=user" endpoint.
Recommendations For Service Provider Management System version 1.0, consider disabling access to the "/php-spms/admin/?page=user" endpoint until a patch is available. As a temporary workaround, restrict the use of the firstname, middlename, and lastname parameters in this endpoint to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-43456

Produtos afetados

Service Provider Management System