CVE-2023-5695
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-5695 is a newly disclosed vulnerability affecting CodeAstro Internet Banking System 1.0. The issue lies within the functionality of the file pages_reset_pwd.php. An attacker can exploit this vulnerability by manipulating the email argument with input like testing%40example.com'%26%25<ScRiPt%20>alert(9860)</ScRiPt>. This results in a cross-site scripting (XSS) attack, which can be launched remotely. The exploit has become publicly known, increasing the risk of potential attacks. The Vulnerability Database has assigned the identifier VDB-243133 to this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.