SourceCodester Online Learning System V2 index.php cross site scripting
Published Feb 28, 2024
6.1
MEDIUMCVSS 3.1
EPSS 0.71%
Description
A vulnerability, which was classified as problematic, was found in SourceCodester Online Learning System V2 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255126 is the identifier assigned to this vulnerability.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SourceCodester | Online Learning System V2 | n/a |
|
- 2.0
-
- Version 1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SourceCodester | Online Learning System V2 | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/OnlineLearningSystemV2-XSS.md exploit
- https://vuldb.com/?ctiid.255126 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.255126 vdb-entrytechnical-descriptionPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/OnlineLearningSystemV2-XSS.md | exploit | |
| https://vuldb.com/?ctiid.255126 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.255126 | vdb-entrytechnical-descriptionPermissions Required |
Change history (0)
No recorded changes yet.