Cross-Site Scripting Vulnerability in User Registration and Login System by PHP Gurukul
CVE-2023-33591
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 21 June 2023
What is CVE-2023-33591?
A vulnerability has been identified in version 1.0 of the User Registration & Login and User Management System by PHP Gurukul, which allows attackers to exploit a cross-site scripting (XSS) flaw. The issue is found in the /admin/search-result.php component, potentially enabling unauthorized script execution. This can lead to session hijacking, data theft, and manipulation, emphasizing the importance of applying security patches and validating user inputs to mitigate risks.
