Vulnerability Description
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inventory System Project | Inventory System | <= 2021-04-23 |
Related Weaknesses (CWE)
References
- https://gist.github.com/enferas/649f39c955ce2816ba1abae620e749c7ExploitThird Party Advisory
- https://github.com/ronknight/InventorySystem/issues/23ExploitIssue TrackingThird Party Advisory
- https://gist.github.com/enferas/649f39c955ce2816ba1abae620e749c7ExploitThird Party Advisory
- https://github.com/ronknight/InventorySystem/issues/23ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2023-23014?
CVE-2023-23014 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.ph...
How severe is CVE-2023-23014?
CVE-2023-23014 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-23014?
Check the references section above for vendor advisories and patch information. Affected products include: Inventory System Project Inventory System.