A vulnerability, which was classified as problematic, was found in Badminton Center Management System. This affects the userlist module at /bcms/admin/?page=user/list. The manipulation of the argument username with the input
1 leads to an authenticated cross site scripting. Exploit details have been disclosed to the public.
Vector :
Exploitability : 6.8 / Impact
: 2.9
Confidentiality Impact
NONE
5.4 /10
CVSS v3.0 : MEDIUM
Vector :
Exploitability : 2.3 / Impact
: 2.7
User Interaction
REQUIRED
Confidentiality Impact
LOW
Configuration 1
cpe:2.3:a:badminton_center_management_system_project:badminton_center_management_system:1.0:*:*:*:*:*:*:* |
|
24 Jan 2023, 16:19
Type |
Values Removed |
Values Added |
CPE |
|
cpe:2.3:a:predictapp_project:predictapp:*:*:*:*:*:*:*:* |
References |
(MISC) https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 - |
(MISC) https://github.com/abhilash1985/PredictApp/commit/b067372f3ee26fe1b657121f0f41883ff4461a06 - Patch, Third Party Advisory |
References |
(MISC) https://github.com/abhilash1985/PredictApp/pull/73 - |
(MISC) https://github.com/abhilash1985/PredictApp/pull/73 - Patch, Third Party Advisory |
References |
(MISC) https://vuldb.com/?id.218387 - |
(MISC) https://vuldb.com/?id.218387 - Third Party Advisory |
References |
(MISC) https://vuldb.com/?ctiid.218387 - |
(MISC) https://vuldb.com/?ctiid.218387 - Third Party Advisory |
CVSS |
v2 : unknown
v3 : unknown
|
v2 : unknown
v3 : 9.8
|
First Time |
|
Predictapp Project predictapp
Predictapp Project
|
16 Jan 2023, 13:15
Type |
Values Removed |
Values Added |
New CVE |
|