PT-2023-17170 · Sourcecodester · Sourcecodester Simple Task Allocation System

·

CVE-2023-1687

·

Published

2023-03-29

·

Updated

2024-05-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Simple Task Allocation System version 1.0
Description A problematic issue has been discovered, allowing for cross-site scripting through the manipulation of the Fullname argument in the "LoginRegistration.php?a=register user" endpoint. This can be exploited remotely.
Recommendations For SourceCodester Simple Task Allocation System version 1.0, consider restricting access to the "LoginRegistration.php?a=register user" endpoint until a fix is available, and avoid using the Fullname argument in this context to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-1687

Affected Products

Sourcecodester Simple Task Allocation System