PT-2024-23169 · Unknown · Bdtask Multi-Store Inventory Management System

Srivishnu

·

Published

2024-03-27

·

Updated

2025-06-12

·

CVE-2024-2996

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bdtask Multi-Store Inventory Management System versions up to 20240320
Description A vulnerability was found in the Page Title Handler component of the system, which can lead to cross-site scripting. The manipulation can be launched remotely. The vendor was contacted about this disclosure but did not respond.
Recommendations For versions up to 20240320, as a temporary workaround, consider restricting access to the Page Title Handler component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-2996

Affected Products

Bdtask Multi-Store Inventory Management System