Medium severity5.4NVD Advisory· Published Dec 7, 2023· Updated Jun 17, 2026
CVE-2023-48172
CVE-2023-48172
Description
A Cross Site Scripting (XSS) vulnerability in Shuttle Booking Software 2.0 allows a remote attacker to inject JavaScript via the name, description, title, or address parameter to index.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <2.0
- Shuttle Booking Software/Shuttle Booking Softwaredescription
- cpe:2.3:a:phpjabbers:shuttle_booking_software:2.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/bugsbd/CVE/tree/main/2023/CVE-2023-48172nvdExploit
- packetstormsecurity.com/files/175800nvdThird Party AdvisoryVDB Entry
- www.phpjabbers.com/shuttle-booking-software/nvdProduct
News mentions
0No linked articles in our index yet.