Cross Site Scripting Vulnerability in IT Sourcecode Content Management System by TzssZ
CVE-2023-31816

6.1MEDIUM

What is CVE-2023-31816?

The IT Sourcecode Content Management System, specifically version 1.0.0, is susceptible to a Cross Site Scripting (XSS) vulnerability. This flaw arises in the search_list.php component, where unvalidated input can be executed in the browser of any user accessing this page. Attackers can exploit this vulnerability to inject arbitrary scripts, potentially compromising user data and session security. It's vital for users of this software to implement security patches and input validation measures to safeguard against such exploits. For more detailed information, you can reference the GitHub report.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.