Vulnerability Description
A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /accounts_con/register_account. The manipulation of the argument Username with the input <script>alert(document.cookie)</script> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247910 is the identifier assigned to this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codeastro | Pos And Inventory Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://drive.google.com/drive/folders/1wnrdIuBhZh5ia9Q61b_V_72eIaHsX-B1?usp=shaExploit
- https://vuldb.com/?ctiid.247910Third Party Advisory
- https://vuldb.com/?id.247910Third Party Advisory
- https://drive.google.com/drive/folders/1wnrdIuBhZh5ia9Q61b_V_72eIaHsX-B1?usp=shaExploit
- https://vuldb.com/?ctiid.247910Third Party Advisory
- https://vuldb.com/?id.247910Third Party Advisory
FAQ
What is CVE-2023-6774?
CVE-2023-6774 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A vulnerability was found in CodeAstro POS and Inventory Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /accounts_con/register_ac...
How severe is CVE-2023-6774?
CVE-2023-6774 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6774?
Check the references section above for vendor advisories and patch information. Affected products include: Codeastro Pos And Inventory Management System.