Cross-Site Scripting Vulnerability in Online Food Ordering System by Xiumulty
CVE-2023-24192
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 6 February 2023
What is CVE-2023-24192?
An XSS vulnerability has been identified in the Online Food Ordering System v2 that allows attackers to inject malicious scripts through the redirect parameter in the login.php file. This weakness can lead to unauthorized actions being performed on behalf of an unsuspecting user, potentially compromising sensitive data and session information. Anyone using this version should promptly address this flaw to mitigate potential security risks.
