{ "id": "CVE-2023-49539", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-01T22:15:47.540", "lastModified": "2024-03-01T22:22:25.913", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter." }, { "lang": "es", "value": "Se descubri\u00f3 que Book Store Management System v1.0 conten\u00eda una vulnerabilidad de Cross-Site Scripting (XSS) en /bsms_ci/index.php/category. Esta vulnerabilidad permite a los atacantes ejecutar scripts web o HTML arbitrarios a trav\u00e9s de un payload manipulado inyectado en el par\u00e1metro de categor\u00eda." } ], "metrics": {}, "references": [ { "url": "https://github.com/geraldoalcantara/CVE-2023-49539", "source": "cve@mitre.org" }, { "url": "https://owasp.org/Top10/A03_2021-Injection/", "source": "cve@mitre.org" }, { "url": "https://owasp.org/www-community/attacks/xss/", "source": "cve@mitre.org" }, { "url": "https://www.sourcecodester.com/php/15748/book-store-management-system-project-using-php-codeigniter-3-free-source-code.html", "source": "cve@mitre.org" } ] }