PT-2024-30159 · Unknown · Kashipara Music Management System

Published

2024-08-26

·

Updated

2024-08-30

·

CVE-2024-42787

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kashipara Music Management System version 1.0
Description A Stored Cross Site Scripting (XSS) issue was found in the "/music/ajax.php?action=save playlist" endpoint, allowing remote attackers to execute arbitrary code via the title and description parameter fields. This could potentially lead to account compromise and data theft.
Recommendations For Kashipara Music Management System version 1.0, upgrade to version 1.1 to mitigate the risks associated with this issue. As a temporary workaround, consider validating user input for the title and description fields in the "/music/ajax.php?action=save playlist" endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-42787

Affected Products

Kashipara Music Management System