PT-2024-17802 · Code Projects · Simple Admin Panel

Havook

·

Published

2024-12-26

·

Updated

2024-12-26

·

CVE-2024-12932

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Simple Admin Panel version 1.0
Description A problem was discovered in the file addSizeController.php, where the manipulation of the size argument leads to cross-site scripting. The attack can be launched remotely.
Recommendations For version 1.0, consider disabling the functionality related to the addSizeController.php file until a patch is available. Restrict access to the addSizeController.php file to minimize the risk of exploitation. Avoid using the size argument in the affected functionality until the issue is resolved.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-12932

Affected Products

Simple Admin Panel