Cross Site Scripting Vulnerability in Sourcecodester Expense Tracker App
CVE-2023-44048
5.4MEDIUM
What is CVE-2023-44048?
The Sourcecodester Expense Tracker App version 1 contains a vulnerability that allows an attacker to exploit Cross Site Scripting (XSS) through the 'add category' feature. This flaw can enable unauthorized users to inject malicious scripts that may compromise user data, leading to severe security risks such as session hijacking or unauthorized actions performed on behalf of legitimate users. It is crucial for users and developers to patch this vulnerability to enhance the overall security of their web applications.