Required CVE Record Information
Description
A vulnerability classified as problematic has been found in Campcodes Complete Online DJ Booking System 1.0. Affected is an unknown function of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257472.
CVSS 3 Total
Score | Severity | Version | Vector String |
---|---|---|---|
3.5 | LOW | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
3.5 | LOW | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
4.0 | — | 2.0 | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Credits
- SSL_Seven_Security Lab_WangZhiQiang_XiaoZiLong (VulDB User) reporter
References 3 Total
- vuldb.com: VDB-257472 | Campcodes Complete Online DJ Booking System admin-profile.php cross site scripting vdb-entrytechnical-description
- vuldb.com: VDB-257472 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20DJ%20Booking%20System/Complete%20Online%20DJ%20Booking%20System%20-%20vuln%208.pdf exploit
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- vuldb.com: VDB-257472 | Campcodes Complete Online DJ Booking System admin-profile.php cross site scripting vdb-entrytechnical-descriptionx_transferred
- vuldb.com: VDB-257472 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-requiredx_transferred
- https://github.com/E1CHO/cve_hub/blob/main/Complete%20Online%20DJ%20Booking%20System/Complete%20Online%20DJ%20Booking%20System%20-%20vuln%208.pdf exploitx_transferred