PT-2024-13037 · Unknown · Code-Projects Exam Form Submission

Aaditya Singh Rajawat

·

Published

2024-03-12

·

Updated

2024-08-21

·

CVE-2023-42308

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Code-Projects Exam Form Submission version 1.0
Description The issue allows attackers to run arbitrary code via the Subject Name and Subject Code sections, potentially leading to unauthorized actions. This is a Cross Site Scripting (XSS) issue.
Recommendations For Code-Projects Exam Form Submission version 1.0, consider validating and sanitizing user input in the Subject Name and Subject Code sections to prevent the execution of arbitrary code. As a temporary workaround, restrict access to these sections until a proper fix is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-42308

Affected Products

Code-Projects Exam Form Submission