Cross Site Scripting Vulnerability in Phpgurukul Park Ticketing Management System
CVE-2023-26958
4.8MEDIUM
Key Information:
- Vendor
PHPgurukul
- Vendor
- CVE Published:
- 27 March 2023
What is CVE-2023-26958?
The Park Ticketing Management System 1.0 developed by Phpgurukul is susceptible to a Cross Site Scripting (XSS) attack through the Admin Name parameter. This vulnerability allows attackers to inject malicious scripts, potentially compromising user sessions and sensitive information. Proper validation and sanitization of input data are essential to mitigate this risk.