Vulnerability Description
A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad-has-principes/ of the component HTTP POST Request Handler. The manipulation of the argument username/title/comment leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-233888.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gzscripts | Vacation Rental Website | 1.8 |
Related Weaknesses (CWE)
References
- https://vuldb.com/?ctiid.233888Third Party Advisory
- https://vuldb.com/?id.233888Permissions RequiredThird Party Advisory
- https://vuldb.com/?ctiid.233888Third Party Advisory
- https://vuldb.com/?id.233888Permissions RequiredThird Party Advisory
FAQ
What is CVE-2023-3642?
CVE-2023-3642 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability was found in GZ Scripts Vacation Rental Website 1.8 and classified as problematic. Affected by this issue is some unknown functionality of the file /VacationRentalWebsite/property/8/ad...
How severe is CVE-2023-3642?
CVE-2023-3642 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3642?
Check the references section above for vendor advisories and patch information. Affected products include: Gzscripts Vacation Rental Website.