Cross-site Scripting Vulnerability in Sourcecodester Online Pizza Ordering System
CVE-2023-37150

6.1MEDIUM

What is CVE-2023-37150?

The Sourcecodester Online Pizza Ordering System v1.0 contains a Cross-site Scripting (XSS) vulnerability located in the '/admin/index.php?page=categories' page. This flaw may allow an attacker to inject malicious scripts into the web application, potentially leading to unauthorized access or manipulation of sensitive data by exploiting users who access vulnerable pages.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.