Sploitus

CVE-2023-6435

No indexed exploits for CVE-2023-6435 yet

A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/batches_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.

Bigprof Online Invoicing System
= 2.6
Fix
Available
CVSS 3.1
6.3 MEDIUM
EPSS
0.4% (32th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2023-11-30
CVE-2023-6435 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-6435 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-6435 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.