PT-2024-38829 · Sourcecodester · Sourcecodester Task Progress Tracker

Jadu101

·

Published

2024-08-24

·

Updated

2024-08-29

·

CVE-2024-8140

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SourceCodester Task Progress Tracker version 1.0
Description: A vulnerability was found in the file update-task.php, where the manipulation of the task name argument leads to cross-site scripting. The attack may be launched remotely. The estimated number of potentially affected devices is not specified.
Recommendations: For version 1.0, upgrade to version 1.1 to remediate this issue. As a temporary workaround, consider restricting access to the update-task.php file and the task name argument to minimize the risk of exploitation. Avoid using the task name argument in the affected functionality until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-8140

Affected Products

Sourcecodester Task Progress Tracker