Lucene search

K
nvd[email protected]NVD:CVE-2023-3986
HistoryJul 28, 2023 - 5:15 a.m.

CVE-2023-3986

2023-07-2805:15:11
CWE-79
web.nvd.nist.gov
2
vulnerability
sourcecodester
cross site scripting
remote attackers
file processing
disclosure
vdb-235607

CVSS2

3.3

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

MULTIPLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:M/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

4

Confidence

High

EPSS

0.001

Percentile

43.9%

A vulnerability was found in SourceCodester Simple Online Mens Salon Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=user/list. The manipulation of the argument First Name/Last Name/Username leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235607.

Affected configurations

Nvd
Node
simple_online_mens_salon_management_system_projectsimple_online_mens_salon_management_systemMatch1.0
VendorProductVersionCPE
simple_online_mens_salon_management_system_projectsimple_online_mens_salon_management_system1.0cpe:2.3:a:simple_online_mens_salon_management_system_project:simple_online_mens_salon_management_system:1.0:*:*:*:*:*:*:*

CVSS2

3.3

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

MULTIPLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:M/C:N/I:P/A:N

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

AI Score

4

Confidence

High

EPSS

0.001

Percentile

43.9%

Related for NVD:CVE-2023-3986