CVE-2023-36159Cross-site Scripting in Lost AND Found Information System

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 73.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 4

Description

Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-7448-crw6-qvfr: Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 12023-08-04
CVEList
CVE-2023-36159: Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 12023-08-03
CVE-2023-36159 — Cross-site Scripting | cvebase