PT-2024-13036 · Unknown · Code-Projects Exam Form Submission

Published

2024-03-12

·

Updated

2025-03-20

·

CVE-2023-42307

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Code-Projects Exam Form Submission version 1.0
Description A Cross Site Scripting (XSS) issue affects the software, allowing attackers to execute arbitrary code through the Subject Name and Subject Code sections. This enables attackers to run arbitrary code via these sections.
Recommendations For version 1.0, consider disabling the Subject Name and Subject Code sections until a patch is available to prevent exploitation. Restrict access to these sections to minimize the risk of arbitrary code execution. Avoid using the Subject Name and Subject Code fields in the affected sections until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-42307

Affected Products

Code-Projects Exam Form Submission