PT-2024-17363 · Sourcecodester · Sourcecodester Testimonial Page Manager

Michael Blunt

+1

·

Published

2024-02-02

·

Updated

2024-06-26

·

CVE-2024-1196

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Testimonial Page Manager version 1.0
Description A vulnerability was found in the HTTP POST Request Handler component, specifically in the file add-testimonial.php. The manipulation of the name, description, or testimony arguments leads to cross-site scripting. The attack can be initiated remotely.
Recommendations For SourceCodester Testimonial Page Manager version 1.0, consider disabling the add-testimonial.php file or restricting access to it until a patch is available. Additionally, avoid using the name, description, and testimony arguments in the affected HTTP POST Request Handler until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1196

Affected Products

Sourcecodester Testimonial Page Manager