CVE-2023-1418
A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0.
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability classified as problematic was found in SourceCodester Friendly Island Pizza Website and Ordering System 1.0. Affected by this vulnerability is an unknown functionality of the file cashconfirm.php of the component POST Parameter Handler. The manipulation of the argument transactioncode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223129 was assigned to this vulnerability.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- friendly island pizza website and ordering system project/friendly island pizza website and ordering system
- Source
- cna@vuldb.com
References
- https://github.com/2889436547/bug_report/blob/main/vendors/Skynidnine/Friendly%20Island%20Pizza%20Website%20and%20Ordering%20System/XSS-1.mdExploit, Vendor Advisory
- https://vuldb.com/?ctiid.223129Permissions Required, Third Party Advisory
- https://vuldb.com/?id.223129Third Party Advisory
- https://github.com/2889436547/bug_report/blob/main/vendors/Skynidnine/Friendly%20Island%20Pizza%20Website%20and%20Ordering%20System/XSS-1.mdExploit, Vendor Advisory
- https://vuldb.com/?ctiid.223129Permissions Required, Third Party Advisory
- https://vuldb.com/?id.223129Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.