Cross Site Scripting Vulnerability in Code-Projects Online Car Rental System
CVE-2024-12998

6.1MEDIUM

Key Information:

Vendor
CVE Published:
28 December 2024

Summary

A vulnerability exists in the Online Car Rental System version 1.0 developed by Code-Projects, particularly within the GET Parameter Handler found in the /index.php file. This security flaw allows for the execution of cross site scripting (XSS) attacks, which can be initiated remotely by an attacker. The improper handling of user input could lead to unauthorized access and manipulation of sensitive data. The vulnerability has been publicly disclosed, raising concerns over its exploitation in real-world scenarios. Users of the affected version are advised to take precautions to mitigate the risks associated with this security issue.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.
CVE-2024-12998 : Cross Site Scripting Vulnerability in Code-Projects Online Car Rental System | SecurityVulnerability.io