PT-2024-16110 · Code Projects · Pharmacy Management System

C4Ttr4Ck

·

Published

2024-10-20

·

Updated

2024-10-23

·

CVE-2024-10197

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Pharmacy Management System version 1.0
Description A security issue has been found in the Manage Supplier Page component, specifically in the file /manage supplier.php. The manipulation of the address argument leads to cross-site scripting. This issue can be exploited remotely. The exploit has been disclosed publicly and may be used. Other parameters might also be affected.
Recommendations For version 1.0, consider disabling the address argument in the /manage supplier.php file until a patch is available. Restrict access to the Manage Supplier Page component to minimize the risk of exploitation. Avoid using the address parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-10197

Affected Products

Pharmacy Management System