Cross-Site Scripting Issue in Online Food Ordering System by SourceCodester
CVE-2023-24194

6.1MEDIUM

What is CVE-2023-24194?

The Online Food Ordering System version 2 has been identified to possess a cross-site scripting (XSS) vulnerability. This vulnerability arises specifically from the mishandling of the 'page' parameter in the navbar.php file, which can be exploited by attackers to inject malicious scripts. Users of the system may be exposed to potential attacks that could manipulate the web application and deceive end-users into performing unintended actions.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.