CVE-2023-6462Cross-site Scripting in User Registration AND Login System

Severity
6.1MEDIUMNVD
CNA3.5
EPSS
0.1%
top 76.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1
Latest updateDec 2

Description

A vulnerability, which was classified as problematic, was found in SourceCodester User Registration and Login System 1.0. Affected is an unknown function of the file /endpoint/delete-user.php. The manipulation of the argument user leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246612.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

🔴Vulnerability Details

2
GHSA
GHSA-p56w-mgwq-3w3q: A vulnerability, which was classified as problematic, was found in SourceCodester User Registration and Login System 12023-12-02
CVEList
SourceCodester User Registration and Login System delete-user.php cross site scripting2023-12-01
CVE-2023-6462 — Cross-site Scripting | cvebase