PT-2022-10910 · Unknown · Online Student Rate System
Stefan Dorresteijn
·
Published
2022-06-24
·
Updated
2022-06-30
·
CVE-2021-39408
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Online Student Rate System version 1.0
Description
A Cross Site Scripting (XSS) issue exists via the
page parameter on the "index.php" file. This allows for potential malicious script execution.Recommendations
For Online Student Rate System version 1.0, consider validating and sanitizing the
page parameter in the "index.php" file to prevent XSS attacks. As a temporary workaround, restrict access to the "index.php" file until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Student Rate System