PT-2019-15399 · Sourcecodester · Sourcecodester Restaurant Management System
Published
2019-10-24
·
Updated
2019-10-28
·
CVE-2019-18416
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sourcecodester Restaurant Management System version 1.0
Description
The issue allows for cross-site scripting (XSS) attacks through the Last Name field of a member. This occurs when an attacker injects malicious code into the
Last Name field, which is then executed by the application.Recommendations
For Sourcecodester Restaurant Management System version 1.0, consider validating and sanitizing user input in the
Last Name field to prevent XSS attacks. As a temporary workaround, restrict user input to only allow alphanumeric characters in the Last Name field until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Restaurant Management System