Cross-Site Scripting Vulnerability in Code-Projects Farmacia Software
CVE-2024-11996
Key Information
- Vendor
- Code-projects
- Status
- Farmacia
- Vendor
- CVE Published:
- 30 November 2024
Badges
Summary
CVE-2024-11996 is a high-risk cross-site scripting (XSS) vulnerability discovered in Code-Projects Farmacia version 1.0. This vulnerability arises from improper validation of user input in the '/editar-fornecedor.php' file, specifically affecting the 'cidade' parameter. Malicious actors can exploit this flaw remotely, potentially leading to unauthorized script execution in the context of the user's browser, allowing them to steal sensitive data or perform actions on behalf of the user. Security measures should be implemented immediately to mitigate this risk, and users are urged to update their software to the latest version.
Affected Version(s)
Farmacia = 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved