Cross Site Scripting Vulnerability in Sourcecodester Expense Tracker App
CVE-2023-44048

5.4MEDIUM

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
27 September 2023

What is CVE-2023-44048?

The Sourcecodester Expense Tracker App version 1 contains a vulnerability that allows an attacker to exploit Cross Site Scripting (XSS) through the 'add category' feature. This flaw can enable unauthorized users to inject malicious scripts that may compromise user data, leading to severe security risks such as session hijacking or unauthorized actions performed on behalf of legitimate users. It is crucial for users and developers to patch this vulnerability to enhance the overall security of their web applications.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.