SourceCodester Online Food Ordering System Category List cross site scripting
Summary
| CVE | CVE-2023-0258 |
|---|---|
| State | PUBLISHED |
| Assigner | VulDB |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-12 22:15:09 UTC |
| Updated | 2026-03-30 18:15:59 UTC |
| Description | A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Category List Handler. The manipulation of the argument Reason with the input "><script>prompt(1)</script> leads to cross site scripting. The attack may be launched remotely. VDB-218186 is the identifier assigned to this vulnerability. |
Risk And Classification
Primary CVSS: v3.1 6.1 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-79 | CWE-79 CWE-79 Cross Site Scripting
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | [email protected] | Secondary | 2.4 | LOW | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
| 3.1 | CNA | DECLARED | 2.4 | LOW | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
| 3.0 | CNA | DECLARED | 2.4 | LOW | CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
| 2.0 | [email protected] | Secondary | 3.3 | AV:N/AC:L/Au:M/C:N/I:P/A:N | |
| 2.0 | CNA | DECLARED | 3.3 | AV:N/AC:L/Au:M/C:N/I:P/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
MultipleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:M/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oretnom23 | Online Food Ordering System | 2.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SourceCodester | Online Food Ordering System | affected 2.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vuldb.com | af854a3a-2127-422b-91ae-364da2661108 | vuldb.com | Permissions Required, Third Party Advisory |
| vuldb.com | af854a3a-2127-422b-91ae-364da2661108 | vuldb.com | Permissions Required, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: lucifoxer001 (VulDB User) (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-01-12T00:00:00.000Z | Advisory disclosed |
| CNA | 2023-01-12T00:00:00.000Z | CVE reserved |
| CNA | 2023-01-12T01:00:00.000Z | VulDB entry created |
| CNA | 2023-02-05T10:27:03.000Z | VulDB entry last update |
There are currently no legacy QID mappings associated with this CVE.