Cross-Site Scripting (XSS) vulnerability in Cups Easy
CVE-2024-23881
What is CVE-2024-23881?
A security issue has been identified in Cups Easy (Purchase & Inventory), specifically in version 1.0. This vulnerability arises from insufficient encoding of user-controlled inputs, leading to a Cross-Site Scripting (XSS) risk through a flaw in the description parameter of the endpoint /cupseasylive/statelist.php. If exploited, a remote attacker could craft a malicious URL, which, when interacted with by an authenticated user, could enable the theft of their session cookie credentials, potentially allowing unauthorized access to their account.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cups Easy (Purchase & Inventory) 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
