Cross Site Scripting Vulnerability in Testimonial Page Manager 1.0
CVE-2024-1196

6.1MEDIUM

Key Information:

Vendor
CVE Published:
2 February 2024

Summary

A cross-site scripting vulnerability exists within the SourceCodester Testimonial Page Manager, specifically associated with the HTTP POST Request Handler in the add-testimonial.php file. This vulnerability allows for the exploitation of user inputs, such as name, description, and testimony fields, resulting in potential execution of arbitrary scripts in the context of a victim's browser. Attackers can initiate these attacks remotely, leveraging the security flaw to manipulate the input data and execute malicious payloads. Proper validation and sanitization of user input are essential to mitigate this security risk.

Affected Version(s)

Testimonial Page Manager 1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Blunt
mikel22 (VulDB User)
.