Cross-Site Scripting Vulnerability in code-projects Simple Admin Panel
CVE-2024-12933

5.3MEDIUM

Key Information:

Vendor
CVE Published:
26 December 2024

Summary

A cross-site scripting vulnerability exists in the updateItemController.php file of code-projects' Simple Admin Panel version 1.0. This vulnerability arises when the parameters 'p_name' or 'p_desc' are manipulated, potentially allowing attackers to inject malicious scripts that can be executed in the context of an unsuspecting user's browser. As a result, the exploitation of this flaw can lead to unauthorized actions or the theft of sensitive user information. Attackers can exploit this vulnerability remotely, which increases its potential impact on users and organizations relying on this web application.

Affected Version(s)

Simple Admin Panel 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fergod (VulDB User)
.