• caglararli@hotmail.com
  • 05386281520

CVE-2023-7124 | code-projects E-Commerce Site 1.0 search.php keyword cross site scripting

Çağlar Arlı      -    23 Views

CVE-2023-7124 | code-projects E-Commerce Site 1.0 search.php keyword cross site scripting

A vulnerability, which was classified as problematic, was found in code-projects E-Commerce Site 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument keyword with the input <video/src=x onerror=alert(document.cookie)> leads to cross site scripting. This vulnerability is traded as CVE-2023-7124. It is possible to launch the attack remotely. Furthermore, there is an exploit available.