Vulnerability Description
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Hostel Management System | 2.1 |
Related Weaknesses (CWE)
References
- https://medium.com/@ridheshgohil1092/cve-2023-36375-xss-on-hostel-management-sys
- https://packetstormsecurity.comMitigationThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/50628
- https://medium.com/%40ridheshgohil1092/cve-2023-36375-xss-on-hostel-management-sExploitThird Party Advisory
- https://packetstormsecurity.comMitigationThird Party AdvisoryVDB Entry
FAQ
What is CVE-2023-36375?
CVE-2023-36375 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, c...
How severe is CVE-2023-36375?
CVE-2023-36375 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36375?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Hostel Management System.