A vulnerability has been found in SourceCodester User Registration and Login System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument first_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246613 was assigned to this vulnerability.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/qqisee/vulndis/blob/main/xss_add_user.md | Exploit Third Party Advisory | 
| https://vuldb.com/?ctiid.246613 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.246613 | Third Party Advisory | 
| https://github.com/qqisee/vulndis/blob/main/xss_add_user.md | Exploit Third Party Advisory | 
| https://vuldb.com/?ctiid.246613 | Permissions Required Third Party Advisory | 
| https://vuldb.com/?id.246613 | Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 08:43
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/qqisee/vulndis/blob/main/xss_add_user.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.246613 - Permissions Required, Third Party Advisory | |
| References | () https://vuldb.com/?id.246613 - Third Party Advisory | |
| CVSS | v2 : v3 : | v2 : 4.0 v3 : 3.5 | 
06 Dec 2023, 20:10
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 5.4 | 
| CPE | cpe:2.3:a:remyandrade:user_registration_and_login_system:1.0:*:*:*:*:*:*:* | |
| First Time | Remyandrade Remyandrade user Registration And Login System | |
| References | () https://github.com/qqisee/vulndis/blob/main/xss_add_user.md - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?id.246613 - Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.246613 - Permissions Required, Third Party Advisory | 
01 Dec 2023, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-12-01 23:15
Updated : 2024-11-21 08:43
NVD link : CVE-2023-6463
Mitre link : CVE-2023-6463
CVE.ORG link : CVE-2023-6463
JSON object : View
Products Affected
                remyandrade
- user_registration_and_login_system
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
