Cross Site Scripting in GaatiTrack Courier Management System
CVE-2023-48206

6.1MEDIUM

Key Information:

Vendor

Mayurik

Vendor
CVE Published:
7 December 2023

What is CVE-2023-48206?

The GaatiTrack Courier Management System version 1.0 is susceptible to a Cross Site Scripting (XSS) vulnerability. An attacker can exploit this flaw by injecting malicious JavaScript code through the 'page' parameter in the login.php or header.php files, potentially leading to unauthorized actions or data exposure for users accessing the affected systems.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.