PT-2024-30159 · Unknown · Kashipara Music Management System
Published
2024-08-26
·
Updated
2024-08-30
·
CVE-2024-42787
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kashipara Music Management System version 1.0
Description
A Stored Cross Site Scripting (XSS) issue was found in the "/music/ajax.php?action=save playlist" endpoint, allowing remote attackers to execute arbitrary code via the
title and description parameter fields. This could potentially lead to account compromise and data theft.Recommendations
For Kashipara Music Management System version 1.0, upgrade to version 1.1 to mitigate the risks associated with this issue. As a temporary workaround, consider validating user input for the
title and description fields in the "/music/ajax.php?action=save playlist" endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kashipara Music Management System