Cross-Site Scripting Vulnerability in User Registration and Login System by PHP Gurukul
CVE-2023-33591

6.1MEDIUM

What is CVE-2023-33591?

A vulnerability has been identified in version 1.0 of the User Registration & Login and User Management System by PHP Gurukul, which allows attackers to exploit a cross-site scripting (XSS) flaw. The issue is found in the /admin/search-result.php component, potentially enabling unauthorized script execution. This can lead to session hijacking, data theft, and manipulation, emphasizing the importance of applying security patches and validating user inputs to mitigate risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.