Reflected Cross-Site Scripting Vulnerability in Purchase Order Management by Oretnom23
CVE-2023-29623
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 14 April 2023
What is CVE-2023-29623?
A reflected cross-site scripting vulnerability has been identified in the Purchase Order Management application version 1.0. This flaw allows an attacker to exploit the application by sending a crafted request to the password parameter located at /purchase_order/classes/login.php. If a user interacts with this request, malicious scripts can be executed in their browser, leading to potential theft of sensitive information or session hijacking. This vulnerability emphasizes the need for robust input validation and security measures to prevent such exploitations.
