Cross-Site Scripting Flaw in User Registration & Login System
CVE-2023-27225

5.4MEDIUM

What is CVE-2023-27225?

The vulnerability in the User Registration & Login and User Management System with Admin Panel v3 allows attackers to inject malicious scripts into the first and last name fields. When these fields are not properly sanitized, it enables the execution of arbitrary HTML or web scripts in the context of a logged-in user, potentially compromising user data and security. This flaw emphasizes the importance of input validation to prevent XSS attacks, ensuring that user-generated content cannot be exploited for malicious purposes.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.