Cross-Site Scripting Vulnerability in Online Food Ordering System by Xiumulty
CVE-2023-24192

6.1MEDIUM

What is CVE-2023-24192?

An XSS vulnerability has been identified in the Online Food Ordering System v2 that allows attackers to inject malicious scripts through the redirect parameter in the login.php file. This weakness can lead to unauthorized actions being performed on behalf of an unsuspecting user, potentially compromising sensitive data and session information. Anyone using this version should promptly address this flaw to mitigate potential security risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.