We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Assigner | Fluid Attacks |
Reserved | 2023-09-29 |
Published | 2023-10-31 |
Updated | 2024-09-06 |
Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstName' parameter of the users/register.php resource is copied into the users/member.php document as plain text between tags. Any input is echoed unmodified in the users/member.php response.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
https://fluidattacks.com/advisories/carpenter/