PT-2024-39119 · Sourcecodester · Sourcecodester Online Dj Management System
Niu-Zida
·
Published
2024-09-08
·
Updated
2024-09-10
·
CVE-2024-8583
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
SourceCodester Online Bank Management System version 1.0
Description:
A vulnerability was found in the component Feedback Handler, affecting an unknown part of the file
/mfeedback.php. The manipulation leads to cross-site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Recommendations:
For version 1.0, consider disabling the Feedback Handler component until a patch is available to prevent cross-site scripting attacks. Restrict access to the
/mfeedback.php file to minimize the risk of exploitation. Avoid using the Feedback Handler functionality until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Online Dj Management System