CVE-2023-36337Cross-site Scripting in Management System Project Inventory Management System

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 79.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15

Description

A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

🔴Vulnerability Details

2
GHSA
GHSA-pmq2-9644-7v7w: A reflected cross-site scripting (XSS) vulnerability in the component /index2025-12-15
CVEList
CVE-2023-36337: A reflected cross-site scripting (XSS) vulnerability in the component /index2025-12-15
CVE-2023-36337 — Cross-site Scripting | cvebase