A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to launch the attack remotely. VDB-195786 is the identifier assigned to this vulnerability.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://vuldb.com/?id.195786 | third party advisory vdb entry permissions required technical description |
https://vuldb.com/?ctiid.195786 | signature third party advisory vdb entry permissions required |
https://www.sourcecodester.com/php/15238/event-management-system-project-php-source-code.html? | third party advisory related |