Cross Site Scripting Vulnerability in Online DJ Booking System 1.0
CVE-2024-2715
Summary
A cross-site scripting vulnerability exists in the Campcodes Complete Online DJ Booking System 1.0 within the '/admin/user-search.php' file. This vulnerability can be exploited by manipulating the 'searchdata' input parameter, potentially allowing attackers to execute arbitrary JavaScript code in the context of the user's browser. As the exploit can be carried out remotely, it poses a significant threat to users interacting with the affected system. Precautionary measures including proper input validation and output encoding are recommended to mitigate this risk.
Affected Version(s)
Complete Online DJ Booking System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved