Cross Site Scripting Vulnerability in Code-Projects Online Car Rental System
CVE-2024-12998
6.1MEDIUM
What is CVE-2024-12998?
A vulnerability exists in the Online Car Rental System version 1.0 developed by Code-Projects, particularly within the GET Parameter Handler found in the /index.php file. This security flaw allows for the execution of cross site scripting (XSS) attacks, which can be initiated remotely by an attacker. The improper handling of user input could lead to unauthorized access and manipulation of sensitive data. The vulnerability has been publicly disclosed, raising concerns over its exploitation in real-world scenarios. Users of the affected version are advised to take precautions to mitigate the risks associated with this security issue.