Code-Projects Simple Scheduling System Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Code-Projects Simple Scheduling System version 1.0. The issue arises in the Subject Description field, where users can inject malicious JavaScript code. This injected script could be executed when an administrator views the subject information, potentially leading to the theft of the administrator's cookie data.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, add a new subject and enter malicious JavaScript code in the Subject Description field. Once the subject is saved, an administrator can view the subject information, which will trigger the execution of the injected script.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
