PT-2024-39426 · Sourcecodester · Sourcecodester Profile Registration Without Reload Refresh
Jadu101
·
Published
2024-09-22
·
Updated
2024-09-27
·
CVE-2024-9092
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SourceCodester Profile Registration without Reload Refresh version 1.0
Description
A problem was found in the Registration Form component of the file add.php, which can lead to cross site scripting when the
full name argument is manipulated. This issue can be exploited remotely, and the exploit has been disclosed to the public. Other parameters might also be affected.Recommendations
For version 1.0, consider disabling the Registration Form component in the file add.php until a patch is available. As a temporary workaround, restrict the use of the
full name argument to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Profile Registration Without Reload Refresh