VulnerabilityModified
CVE-2023-36317
Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.
MEDIUM 4.8EPSS 0.60%
Does this matter?
Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.
Description
Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- oretnom23/student study center desk management system
- Source
- cve@mitre.org
References
- https://github.com/oye-ujjwal/CVE/blob/main/CVE-2023-36317Exploit, Third Party Advisory
- https://www.sourcecodester.comNot Applicable
- https://www.sourcecodester.com/php/16298/student-study-center-desk-management-system-using-php-oop-and-mysql-db-free-source-codeProduct
- https://github.com/oye-ujjwal/CVE/blob/main/CVE-2023-36317Exploit, Third Party Advisory
- https://www.sourcecodester.comNot Applicable
- https://www.sourcecodester.com/php/16298/student-study-center-desk-management-system-using-php-oop-and-mysql-db-free-source-codeProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.