PT-2023-23425 · Sourcecodester · Sourcecodester Task Reminder System

D34Dun1C02N

+1

·

Published

2023-07-13

·

Updated

2023-07-21

·

CVE-2023-31705

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Task Reminder System version 1.0
Description A Reflected Cross-site scripting (XSS) vulnerability allows an authenticated user to inject malicious javascript into the page parameter. This issue enables attackers to execute malicious scripts on the client-side, potentially leading to unauthorized actions or data theft.
Recommendations For Sourcecodester Task Reminder System version 1.0, consider restricting access to the page parameter to prevent malicious javascript injection until a patch is available. As a temporary workaround, disabling the ability for authenticated users to modify the page parameter may help minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-31705

Affected Products

Sourcecodester Task Reminder System