NA

CVE-2023-43456

Published: 25/09/2023 Updated: 25/09/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote malicious user to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oretnom23 service provider management system 1.0