A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting.
The attack can be initiated remotely. The exploit has been made public and could be used.
Характеристики атаки
Последствия
Строка CVSS v4.0