Cross-Site Scripting Vulnerability in Bdtask Multi-Store Inventory Management System
CVE-2024-2998

5.4MEDIUM

Key Information:

Vendor

Bdtask

Vendor
CVE Published:
27 March 2024

What is CVE-2024-2998?

A vulnerability exists in the Bdtask Multi-Store Inventory Management System affecting versions up to 20240320. Specifically, the Store Update Page is prone to cross-site scripting (XSS) due to improper handling of user input for Store Name and Store Address fields. This flaw allows remote attackers to execute arbitrary scripts in the context of the user's browser, potentially leading to data theft and unauthorized actions. The affected vendor has not responded to early notifications about this issue, increasing the urgency for users to review their systems and apply appropriate mitigations.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.