Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
References
Configurations
Configuration 1 (hide)
|
History
09 Aug 2023, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Aug 2023, 19:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Lost And Found Information System Project lost And Found Information System
Lost And Found Information System Project |
|
| CWE | CWE-79 | |
| References | (MISC) https://www.sourcecodester.com/php/16525/lost-and-found-information-system-using-php-and-mysql-db-source-code-free-download.html - Product | |
| References | (MISC) http://lost.com - Not Applicable | |
| CPE | cpe:2.3:a:lost_and_found_information_system_project:lost_and_found_information_system:1.0:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
04 Aug 2023, 02:45
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-08-04 00:15
Updated : 2023-08-09 21:15
NVD link : CVE-2023-36159
Mitre link : CVE-2023-36159
JSON object : View
Products Affected
lost_and_found_information_system_project
- lost_and_found_information_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
