PT-2023-30980 · Unknown · Car Rental Script

Published

2023-12-07

·

Updated

2023-12-09

·

CVE-2023-48837

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Car Rental Script version 3.0
Description The issue concerns Multiple HTML Injection problems. These issues can be exploited via the SMS API Key or Default Country Code.
Recommendations For Car Rental Script version 3.0, update the software to a version that fixes the Multiple HTML Injection issues, specifically ensuring the SMS API Key and Default Country Code are properly sanitized to prevent HTML injection. As a temporary workaround, consider restricting access to the SMS API Key and Default Country Code to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-48837

Affected Products

Car Rental Script