Cross-Site Scripting Issue in Online Food Ordering System by SourceCodester
CVE-2023-24194
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 6 February 2023
What is CVE-2023-24194?
The Online Food Ordering System version 2 has been identified to possess a cross-site scripting (XSS) vulnerability. This vulnerability arises specifically from the mishandling of the 'page' parameter in the navbar.php file, which can be exploited by attackers to inject malicious scripts. Users of the system may be exposed to potential attacks that could manipulate the web application and deceive end-users into performing unintended actions.
