PT-2024-38841 · Sourcecodester · Sourcecodester Qr Code Bookmark System

Jadu101

·

Published

2024-08-25

·

Updated

2024-08-29

·

CVE-2024-8154

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SourceCodester QR Code Bookmark System version 1.0
Description: A vulnerability has been found in the SourceCodester QR Code Bookmark System. The issue affects an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the arguments tbl bookmark id, name, or url leads to cross-site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations: For SourceCodester QR Code Bookmark System version 1.0, upgrade to version 1.1 to mitigate risks. As a temporary workaround, consider restricting access to the /endpoint/update-bookmark.php endpoint until the issue is resolved. Avoid using the arguments tbl bookmark id, name, or url in the affected endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-8154

Affected Products

Sourcecodester Qr Code Bookmark System