CVE-2023-48206

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 7, 2023
Updated: Dec 9, 2023
CWE ID 79

Summary

CVE-2023-48206 is a Cross Site Scripting (XSS) vulnerability affecting GaatiTrack Courier Management System 1.0. This issue allows remote attackers to inject malicious JavaScript code into the login.php or header.php pages through the page parameter. Successful exploitation could lead to unauthorized access to user sessions or data theft. Users are advised to update their systems as soon as possible to mitigate this security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share