PT-2023-27988 · Unknown · Dairy Farm Shop Management System Using Php/Mysql

Shivam Sharma

·

Published

2023-09-11

·

Updated

2023-09-15

·

CVE-2023-41593

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dairy Farm Shop Management System Using PHP and MySQL version 1.1
Description The issue allows attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters. This enables the execution of malicious scripts, potentially leading to unauthorized access or data manipulation.
Recommendations For Dairy Farm Shop Management System Using PHP and MySQL version 1.1, consider disabling the Category and Category Field parameters until a patch is available to prevent the injection of crafted payloads. Restrict access to these parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-41593

Affected Products

Dairy Farm Shop Management System Using Php/Mysql