Cross-Site Scripting Vulnerability in Bdtask Multi-Store Inventory Management System
CVE-2024-2998
5.4MEDIUM
What is CVE-2024-2998?
A vulnerability exists in the Bdtask Multi-Store Inventory Management System affecting versions up to 20240320. Specifically, the Store Update Page is prone to cross-site scripting (XSS) due to improper handling of user input for Store Name and Store Address fields. This flaw allows remote attackers to execute arbitrary scripts in the context of the user's browser, potentially leading to data theft and unauthorized actions. The affected vendor has not responded to early notifications about this issue, increasing the urgency for users to review their systems and apply appropriate mitigations.