Required CVE Record Information
Description
A vulnerability has been found in nafisulbari/itsourcecode Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file editClient.php. The manipulation of the argument AGENT ID leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS 4 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.3 | MEDIUM | 4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
3.5 | LOW | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
3.5 | LOW | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
4.0 | — | 2.0 | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Product Status
Learn moreVersions 1 Total
Default Status: unknown
affected
Versions 1 Total
Default Status: unknown
affected
Credits
- fahadletsleep (VulDB User) reporter
References 3 Total
- vuldb.com: VDB-275917 | nafisulbari/itsourcecode Insurance Management System editClient.php cross site scripting vdb-entrytechnical-description
- vuldb.com: VDB-275917 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- vuldb.com: Submit #393511 | GitHub Insurance Management System 1.0 Cross Site Scripting third-party-advisory