CVE-2023-1569

Severity
5.4MEDIUM
EPSS
0.2%
top 58.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 22

Description

A vulnerability classified as problematic was found in SourceCodester E-Commerce System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/user/controller.php?action=edit. The manipulation of the argument U_NAME with the input alert('1') leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223561 was assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-cxmh-wf23-vhpw: A vulnerability classified as problematic was found in SourceCodester E-Commerce System 12023-03-22
CVEList
SourceCodester E-Commerce System cross site scripting2023-03-22
CVE-2023-1569 (MEDIUM CVSS 5.4) | A vulnerability classified as probl | cvebase.io