PT-2024-29363 · Unknown · Openflights
Xjzzzxx
·
Published
2024-08-29
·
Updated
2026-01-26
·
CVE-2024-41345
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenFlights commit 5234b5b
Description
The issue is a Cross-Site Scripting (XSS) vulnerability found in the php/trip.php file. This allows for malicious scripts to be injected into the website, potentially leading to unauthorized access or control.
Recommendations
For OpenFlights commit 5234b5b, consider disabling access to the php/trip.php file until a patch is available to prevent exploitation of the Cross-Site Scripting vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openflights