SourceCodester Online Eyewear Shop cross site scripting
CVE-2023-0966
8.8HIGH
Summary
A vulnerability exists in the SourceCodester Online Eyewear Shop 1.0 that allows for cross-site scripting through manipulation of the 'id' argument within the 'admin/?page=orders/view_order' functionality. This could enable attackers to execute arbitrary JavaScript in the context of a user's browser, potentially leading to session hijacking or defacement. The exploit is publicly known and remote attacks are possible, making this a significant concern for users of the application.
Affected Version(s)
Online Eyewear Shop 1.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Murasaki (VulDB User)