Cross Site Scripting Vulnerability in Testimonial Page Manager 1.0
CVE-2024-1196
6.1MEDIUM
Summary
A cross-site scripting vulnerability exists within the SourceCodester Testimonial Page Manager, specifically associated with the HTTP POST Request Handler in the add-testimonial.php file. This vulnerability allows for the exploitation of user inputs, such as name, description, and testimony fields, resulting in potential execution of arbitrary scripts in the context of a victim's browser. Attackers can initiate these attacks remotely, leveraging the security flaw to manipulate the input data and execute malicious payloads. Proper validation and sanitization of user input are essential to mitigate this security risk.
Affected Version(s)
Testimonial Page Manager 1.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Blunt
mikel22 (VulDB User)