Cross-Site Scripting Vulnerability in Online Food Ordering System by SourceCodester
CVE-2023-24195
6.1MEDIUM
Key Information:
- Vendor
- CVE Published:
- 6 February 2023
What is CVE-2023-24195?
The Online Food Ordering System v2 has been identified to have a cross-site scripting (XSS) vulnerability, specifically present in the execution of the 'page' parameter in index.php. This flaw can be exploited by attackers to inject malicious scripts into web pages viewed by users, leading to unauthorized access and potential data compromise. Users and administrators are advised to review their systems and apply any necessary security patches to mitigate the risk associated with this vulnerability.
