PT-2024-29363 · Unknown · Openflights

Xjzzzxx

·

Published

2024-08-29

·

Updated

2026-01-26

·

CVE-2024-41345

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenFlights commit 5234b5b
Description The issue is a Cross-Site Scripting (XSS) vulnerability found in the php/trip.php file. This allows for malicious scripts to be injected into the website, potentially leading to unauthorized access or control.
Recommendations For OpenFlights commit 5234b5b, consider disabling access to the php/trip.php file until a patch is available to prevent exploitation of the Cross-Site Scripting vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41345

Affected Products

Openflights