CVE-2023-2153
SourceCodester Complaint Management System POST Parameter editable_ajax.php cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php of the component POST Parameter Handler. The manipulation of the argument value with the input 1><script>alert(666)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-226274 is the identifier assigned to this vulnerability.
Eine Schwachstelle wurde in SourceCodester Complaint Management System 1.0 gefunden. Sie wurde als problematisch eingestuft. Hierbei geht es um eine nicht exakt ausgemachte Funktion der Datei admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php der Komponente POST Parameter Handler. Durch Manipulation des Arguments value mit der Eingabe 1><script>alert(666)</script> mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-04-18 CVE Reserved
- 2023-04-18 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-11-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.226274 | Technical Description |
URL | Date | SRC |
---|---|---|
https://github.com/1406213367/bug_report/blob/main/XSS-1.md | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Complaint Management System Project Search vendor "Complaint Management System Project" | Complaint Management System Search vendor "Complaint Management System Project" for product "Complaint Management System" | 1.0 Search vendor "Complaint Management System Project" for product "Complaint Management System" and version "1.0" | - |
Affected
|