CVE-2023-43456
25.09.2023, 15:15
Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint.
Vendor | Product | Version |
---|---|---|
oretnom23 | service_provider_management_system | 1.0 |
𝑥
= Vulnerable software versions
References