PT-2023-17374 · Unknown · Sourcecodester Online Computer/Laptop Store

Haicheng.Zhang

·

Published

2023-04-08

·

Updated

2024-05-17

·

CVE-2023-1961

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Online Computer and Laptop Store version 1.0
Description A problematic issue has been found, affecting an unknown function of the file "/admin/?page=system info". The manipulation of the System Name argument leads to cross-site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For version 1.0, consider disabling access to the "/admin/?page=system info" endpoint until a patch is available. Restrict the manipulation of the System Name argument to minimize the risk of cross-site scripting exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-1961

Affected Products

Sourcecodester Online Computer/Laptop Store