A vulnerability classified as problematic was found in GZ Scripts PHP GZ Appointment Scheduling Script 1.8. Affected by this vulnerability is an unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be launched remotely. The identifier VDB-233353 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-10-23T20:02:47.889Z

Reserved: 2023-07-08T11:55:08.407Z

Link: CVE-2023-3559

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:56.453Z

cve-icon NVD

Status : Modified

Published: 2023-07-10T16:15:55.950

Modified: 2024-11-21T08:17:32.483

Link: CVE-2023-3559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.