PT-2024-16717 · Codeastro · Codeastro Real Estate Management System

Thrill_Comrade

·

Published

2024-01-31

·

Updated

2024-05-17

·

CVE-2024-1103

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CodeAstro Real Estate Management System version 1.0
Description A problematic issue was found in the CodeAstro Real Estate Management System, affecting some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input <img src=x onerror=alert(document.cookie)> leads to cross-site scripting. The attack may be launched remotely.
Recommendations For CodeAstro Real Estate Management System version 1.0, consider disabling the Feedback Form functionality until a patch is available. Restrict access to the profile.php file to minimize the risk of exploitation. Avoid using the Your Feedback argument in the affected form until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-1103

Affected Products

Codeastro Real Estate Management System