CVE-2023-6442
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Nov 30, 2023
Updated: May 17, 2024
CWE ID 79
Summary
CVE-2023-6442 is a newly disclosed vulnerability affecting the PHPGurukul Nipah Virus Testing Management System version 1.0. This issue lies in an unknown functionality of the file add-phlebotomist.php and allows for cross-site scripting (XSS) attacks. The vulnerability can be exploited remotely by manipulating the empid/fullname argument. The exploit for this issue has been made public, increasing the risk of attacks. Vulnerability Database has assigned the identifier VDB-246445 to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.