VYPR
leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224748.","additionalType":"https://schema.org/SoftwareApplication","sameAs":["https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1796"]},"keywords":"CVE-2023-1796, Sourcecodester Employee Payslip Generator, Sourcecodester Employee Payslip Generator","mentions":[{"@type":"SoftwareApplication","name":"Employee Payslip Generator","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Sourcecodester"}},{"@type":"SoftwareApplication","name":"Employee Payslip Generator","applicationCategory":"SecurityApplication","publisher":{"@type":"Organization","name":"Sourcecodester"}}],"isAccessibleForFree":true},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://portal.vyprsec.ai/"},{"@type":"ListItem","position":2,"name":"CVEs","item":"https://portal.vyprsec.ai/cves"},{"@type":"ListItem","position":3,"name":"CVE-2023-1796","item":"https://portal.vyprsec.ai/cves/CVE-2023-1796"}]}]}
Unrated severityNVD Advisory· Published Apr 2, 2023· Updated Nov 22, 2024

SourceCodester Employee Payslip Generator Create News cross site scripting

CVE-2023-1796

Description

A vulnerability classified as problematic has been found in SourceCodester Employee Payslip Generator 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_position of the component Create News Handler. The manipulation of the argument name with the input leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224748.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.