CVE-2023-48206
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Dec 7, 2023
Updated: Dec 9, 2023
CWE ID 79
Summary
CVE-2023-48206 is a Cross Site Scripting (XSS) vulnerability affecting GaatiTrack Courier Management System 1.0. This issue allows remote attackers to inject malicious JavaScript code into the login.php or header.php pages through the page parameter. Successful exploitation could lead to unauthorized access to user sessions or data theft. Users are advised to update their systems as soon as possible to mitigate this security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share