Description
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this issue is the function save_designation of the file /classes/Master.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271058 is the identifier assigned to this vulnerability.
Eine Schwachstelle wurde in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 gefunden. Sie wurde als problematisch eingestuft. Betroffen davon ist die Funktion save_designation der Datei /classes/Master.php. Durch das Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
| 2024-07-10: | Advisory disclosed |
| 2024-07-10: | VulDB entry created |
| 2024-07-10: | VulDB entry last update |
Credits
Xu Mingming (VulDB User)
References
vuldb.com/?id.271058 (VDB-271058 | SourceCodester Employee and Visitor Gate Pass Logging System Master.php save_designation cross site scripting)
vuldb.com/?ctiid.271058 (VDB-271058 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.370664 (Submit #370664 | sourcecodester Employee and Visitor Gate Pass Logging System v1.0 XSS)
github.com/Xu-Mingming/cve/blob/main/xss1.md
vuldb.com/?id.271058 (VDB-271058 | SourceCodester Employee and Visitor Gate Pass Logging System Master.php save_designation cross site scripting)
vuldb.com/?ctiid.271058 (VDB-271058 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.370664 (Submit #370664 | sourcecodester Employee and Visitor Gate Pass Logging System v1.0 XSS)