PT-2024-22376 · Unknown · Sourcecodester School Task Manager
Published
2024-05-09
·
Updated
2025-02-11
·
CVE-2024-28277
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sourcecodester School Task Manager version 1.0
Description
A vulnerability was identified within the
subject name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This issue allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.Recommendations
For Sourcecodester School Task Manager version 1.0, consider restricting access to the
subject name= parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the subject name= parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester School Task Manager