Reflected Cross-Site Scripting Vulnerability in Purchase Order Management by Oretnom23
CVE-2023-29623
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 14 April 2023
What is CVE-2023-29623?
A reflected cross-site scripting vulnerability has been identified in the Purchase Order Management application version 1.0. This flaw allows an attacker to exploit the application by sending a crafted request to the password parameter located at /purchase_order/classes/login.php. If a user interacts with this request, malicious scripts can be executed in their browser, leading to potential theft of sensitive information or session hijacking. This vulnerability emphasizes the need for robust input validation and security measures to prevent such exploitations.
References
EPSS Score
24% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
