PT-2024-19523 · Unknown · Keerti1924 Secret-Coder-Php-Project

Reiginald

·

Published

2024-03-07

·

Updated

2024-05-17

·

CVE-2024-2266

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions keerti1924 Secret-Coder-PHP-Project version 1.0
Description A vulnerability has been found in the Login Page component, specifically in the file /login.php. The manipulation of the emailcookie and passwordcookie arguments leads to cross-site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations For keerti1924 Secret-Coder-PHP-Project version 1.0, consider disabling the emailcookie and passwordcookie arguments in the /login.php file as a temporary workaround to minimize the risk of exploitation. Restrict access to the Login Page component to minimize the risk of cross-site scripting attacks.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2266

Affected Products

Keerti1924 Secret-Coder-Php-Project