PT-2025-3463 · Sourcecodester · Sourcecodester Packers/Movers Management System

Madhav Shah

·

Published

2025-02-03

·

Updated

2025-02-06

·

CVE-2024-57522

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Packers and Movers Management System version 1.0
Description The issue concerns a Cross Site Scripting (XSS) problem in the Users.php file. An attacker can inject a malicious script into the username or name field during user creation.
Recommendations For SourceCodester Packers and Movers Management System version 1.0, consider validating and sanitizing user input in the username and name fields to prevent malicious script injection until a patch is available. As a temporary workaround, restrict access to the user creation functionality to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-57522

Affected Products

Sourcecodester Packers/Movers Management System