Stored Cross-Site Scripting Vulnerability in PHPJabbers Shared Asset Booking System
CVE-2023-51325

5.4MEDIUM

Key Information:

Vendor
PHPJabbers
Vendor
CVE Published:
20 February 2025

Summary

The Shared Asset Booking System by PHPJabbers, in version 1.0, is susceptible to stored cross-site scripting attacks. This vulnerability arises from insufficient validation of user input in the 'title' and 'name' parameters, allowing an attacker to inject malicious scripts. If exploited, this could enable unauthorized actions or data theft from affected users, posing a significant risk to the integrity of web applications using this system.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.