Cross Site Scripting Vulnerability in Phpgurukul User Registration System
CVE-2023-40851

5.4MEDIUM

What is CVE-2023-40851?

A Cross Site Scripting (XSS) vulnerability exists in the Phpgurukul User Registration & Login System version 3.0. This flaw allows attackers to execute arbitrary scripts through manipulation of the fname, lname, email, and contact fields on the user registration page. Exploiting this vulnerability could result in unauthorized actions on behalf of users, compromising sensitive data and leading to further security breaches. It is crucial for administrators to apply necessary updates and security measures to safeguard against potential attacks.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.