Vulnerability CVE-2023-44484


Published: 2023-10-31   Modified: 2023-11-01

Description:
Online Blood Donation Management System v1.0 is vulnerable to multiple Store Cross-Site Scripting vulnerabilities. The 'firstName' parameter of the users/register.php resource is copied into the users/member.php document as plain text between tags. Any input is echoed unmodified in the users/member.php response.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://projectworlds.in/
https://fluidattacks.com/advisories/carpenter/

Copyright 2026, cxsecurity.com

 

Back to Top