PT-2024-25192 · Sourcecodester · Product Show Room

Published

2024-05-02

·

Updated

2024-07-03

·

CVE-2024-33302

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Product Show Room versions 1.0 and before
Description The issue is related to Cross Site Scripting (XSS) via the Middle Name field under Add Users. This allows for potential malicious script injection.
Recommendations For versions 1.0 and before, consider disabling the Add Users feature or restricting access to it until a fix is available. Avoid using the Middle Name field in the affected area to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-33302

Affected Products

Product Show Room