PT-2024-20287 · Unknown · Sourcecodester Online Food Menu

Buraksevben

·

Published

2024-01-29

·

Updated

2024-02-22

·

CVE-2024-24134

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Online Food Menu version 1.0
Description The issue concerns Cross Site Scripting (XSS) via the Menu Name and Description fields in the Update Menu section. This allows for potential malicious script injection.
Recommendations For Sourcecodester Online Food Menu version 1.0, as a temporary workaround, consider restricting input in the Menu Name and Description fields to minimize the risk of exploitation. Avoid using these fields until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-24134

Affected Products

Sourcecodester Online Food Menu