We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-39707



Assignermitre
Reserved2023-08-07
Published2023-08-25
Updated2024-10-02

Description

A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add Expense parameter under the Expense section.

References

https://www.sourcecodester.com/

https://www.sourcecodester.com/php/16741/free-and-open-source-inventory-management-system-php-source-code.html

https://gist.github.com/Arajawat007/b94d7ce74fcf16014e282a9b525f4555#file-cve-2023-39707

cve.org CVE-2023-39707

nvd.nist.gov CVE-2023-39707

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.