S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-29623 Scanner

CVE-2023-29623 scanner - Cross-Site Scripting (XSS) vulnerability in Purchase Order Management

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-29623
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Purchase Order Management is a software platform used by businesses to manage their purchases and inventory. It allows users to create purchase orders, manage supplier relationships, and track inventory levels. This product streamlines purchasing procedures, reduces costs and ensures timely delivery of goods and services. 

However, this platform has encountered a significant threat in the form of CVE-2023-29623 vulnerability. This vulnerability arises due to a reflected cross-site scripting (XSS) flaw in the password parameter of the login.php file of the purchase_order module. This vulnerability indicates that when a user attempts to log in and enters a malicious script in the password field, the script is then served back to the user, which can result in the exposure of sensitive information and credentials.

Exploitation of the CVE-2023-29623 vulnerability can lead to various potential drawbacks. An attacker can inject malicious scripts into the entire management system, leading to an information breach, loss of control over the system and compromising confidential information, amongst other severe outcomes. Attackers may also leverage the stolen credentials for future fraudulent operations, leading to significant financial damages to the company. 

In conclusion, thanks to the advanced features of s4e.io, businesses can quickly learn about the vulnerabilities in their digital assets. CVE-2023-29623 is a serious threat to businesses that use Purchase Order Management, and the prevention measures mentioned above can help protect organizations from this vulnerability. Periodic reviews and implementation of cybersecurity measures can eradicate current or future vulnerabilities and safeguard sensitive business information.

 

REFERENCES

Solution Advice

To prevent any harmful consequences, businesses must take precautions to protect against CVE-2023-29623. Here are some possible non-exhaustive countermeasures:

  • Companies can install security tools that can identify such vulnerabilities in the system.
  • Enforcing security policies that restrict the use of weak passwords and implement two-factor authentication can prove useful.
  • Implementing proper web application firewalls can help in blocking the harmful script injection attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-29623 scanner - Cross-Site Scripting (XSS) vulnerability in Purchase Order Management S4E