PT-2024-39930 · Unknown · Sourcecodester Online Eyewear Shop

C4Ttr4Ck

·

Published

2024-10-12

·

Updated

2024-10-16

·

CVE-2024-9906

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Online Eyewear Shop version 1.0
Description A vulnerability was found in the software, affecting an unknown function of the file "/admin/?page=inventory/view inventory&id=2". The manipulation of the Code argument leads to cross-site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For version 1.0, consider disabling access to the "/admin/?page=inventory/view inventory&id=2" endpoint until a patch is available. As a temporary workaround, avoid using the Code argument in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-9906

Affected Products

Sourcecodester Online Eyewear Shop