Cross-Site Scripting Vulnerability in Online Nurse Hiring System by Online
CVE-2023-37683

4.8MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
8 August 2023

Summary

The Online Nurse Hiring System v1.0 has been found to have a cross-site scripting (XSS) vulnerability that could allow attackers to inject malicious scripts into the Profile Page of the Admin. This vulnerability poses risks of data compromise and unauthorized access, as it may enable attackers to manipulate session data and perform actions on behalf of legitimate users. Immediate attention to this vulnerability is essential for securing the application and protecting user data.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.