PT-2023-13787 · Unknown · Intern Record System

H4Md153V63N

·

Published

2023-02-18

·

Updated

2025-03-17

·

CVE-2022-40348

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Intern Record System version 1.0
Description The issue is a Cross Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code. This is achieved through the /intern/controller.php endpoint, specifically by manipulating the name and email parameters.
Recommendations For Intern Record System version 1.0, consider validating and sanitizing user input for the name and email parameters in the /intern/controller.php endpoint to prevent XSS attacks. As a temporary workaround, restrict access to the /intern/controller.php endpoint until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-40348

Affected Products

Intern Record System