CVE-2023-2372
published 2023-04-28CVE-2023-2372: A vulnerability, which was classified as problematic, has been found in SourceCodester Online DJ Management System 1.0. Affected by this issue is some unknown…
PriorityP422medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.61%
45.0th percentile
A vulnerability, which was classified as problematic, has been found in SourceCodester Online DJ Management System 1.0. Affected by this issue is some unknown functionality of the file classes/Master.php?f=save_event. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227648.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| online_dj_management_system_project | online_dj_management_system | — | — |
| sourcecodester | online_dj_management_system | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.3LOWAV:N/AC:L/Au:M/C:N/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wvx6-4fjc-w3r7: A vulnerability, which was classified as problematic, has been found in SourceCodester Online DJ Management System 1
ghsa_unreviewed·2023-04-28
CVE-2023-2372 [LOW] CWE-79 GHSA-wvx6-4fjc-w3r7: A vulnerability, which was classified as problematic, has been found in SourceCodester Online DJ Management System 1
A vulnerability, which was classified as problematic, has been found in SourceCodester Online DJ Management System 1.0. Affected by this issue is some unknown functionality of the file classes/Master.php?f=save_event. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227648.
Red Hat
kernel: null_blk: Always check queue mode setting from configfs
vendor_redhat·2025-10-04·CVSS 5.5
CVE-2023-53576 [MEDIUM] CWE-1288 kernel: null_blk: Always check queue mode setting from configfs
kernel: null_blk: Always check queue mode setting from configfs
In the Linux kernel, the following vulnerability has been resolved:
null_blk: Always check queue mode setting from configfs
Make sure to check device queue mode in the null_validate_conf() and
return error for NULL_Q_RQ as we don't allow legacy I/O path, without
this patch we get OOPs when queue mode is set to 1 from configfs,
following are repro steps :-
modprobe null_blk nr_devices=0
mkdir config/nullb/nullb0
echo 1 > config/nullb/nullb0/memory_backed
echo 4096 > config/nullb/nullb0/blocksize
echo 20480 > config/nullb/nullb0/size
echo 1 > config/nullb/nullb0/queue_mode
echo 1 > config/nullb/nullb0/power
Entering kdb (current=0xffff88810acdd080, pid 2372) on processor 42 Oops: (null)
due to oops @ 0xffffffffc041c329
CPU: 42
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-28
Published