CVE-2023-0563
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 37.61% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- phpgurukul/bank locker management system
- Source
- cna@vuldb.com
References
- https://github.com/ctflearner/Vulnerability/blob/main/Bank_Locker_Management_System/BLMS_XSS_IN_ADMIN_BROWSER.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.219717Permissions Required
- https://vuldb.com/?id.219717Third Party Advisory
- https://github.com/ctflearner/Vulnerability/blob/main/Bank_Locker_Management_System/BLMS_XSS_IN_ADMIN_BROWSER.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.219717Permissions Required
- https://vuldb.com/?id.219717Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.