CVE-2023-1852
published 2023-04-05CVE-2023-1852: A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. This vulnerability affects unknown code of the file…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.60%
44.9th percentile
A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. This vulnerability affects unknown code of the file /admin/deduction_edit.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-224992.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| online_payroll_system_project | online_payroll_system | — | — |
| sourcecodester | online_payroll_system | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpxj-qw8x-q3hf: A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1
ghsa_unreviewed·2023-04-05
CVE-2023-1852 [MEDIUM] CWE-79 GHSA-rpxj-qw8x-q3hf: A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1
A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. This vulnerability affects unknown code of the file /admin/deduction_edit.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The identifier of this vulnerability is VDB-224992.
Red Hat
ghostscript: Incomplete fix for CVE-2020-16305
vendor_redhat·2023-08-23·CVSS 5.5
CVE-2023-4042 [MEDIUM] CWE-125 ghostscript: Incomplete fix for CVE-2020-16305
ghostscript: Incomplete fix for CVE-2020-16305
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
Statement: CVE-2020-16305 affected Red Hat Enterprise Linux 6, 7, and 8, but was only intended to be fixed in Red Hat Enterprise Linux 8. (https://access.redhat.com/errata/RHSA-2021:1852 (Red Hat Enterprise Linux 8.4)
That errata provided updates for ghostscript packages,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/E1CHO/cve_hub/blob/main/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide%20-%20vlun%208.pdfhttps://vuldb.com/?ctiid.224992https://vuldb.com/?id.224992https://github.com/E1CHO/cve_hub/blob/main/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide/Online%20Payroll%20System%20in%20PHP%20and%20MySQL%20Free%20Download%20A%20Comprehensive%20Guide%20-%20vlun%208.pdfhttps://vuldb.com/?ctiid.224992https://vuldb.com/?id.224992
2023-04-05
Published