Vulnerability CVE-2023-43456


Published: 2023-09-25

Description:
Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint.

 References:
https://samh4cks.github.io/posts/cve-2023-43456/
https://www.sourcecodester.com/users/tips23
https://www.sourcecodester.com/php/16501/service-provider-management-system-using-php-and-mysql-source-code-free-download.html

Copyright 2026, cxsecurity.com

 

Back to Top