PHPGurukul Art Gallery Management System
cpe:2.3:a:phpgurukul:art_gallery_management_system:*:*:*:*:*:*:*
- 1.0
A reflected cross-site scripting vulnerability has been identified in PHPGurukul Art Gallery Management System version 1.0. The issue resides in the search.php file, where the search parameter is not properly sanitized, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely, potentially executing harmful scripts in the context of the user's browser.
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the user's browser session.
To reproduce this vulnerability, navigate to the search.php page of the Art Gallery Management System. In the 'Search' input box, enter a script payload, such as a script tag containing JavaScript code, such as an alert. After submitting the search, the injected script will execute, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.