Reflected XSS Vulnerability in Ticket Scanner
CVE-2024-35652
7.1HIGH
Key Information:
- Vendor
- Saso Nikolov
- Status
- Event Tickets With Ticket Scanner
- Vendor
- CVE Published:
- 4 June 2024
Summary
The vulnerability in the Event Tickets with Ticket Scanner by Saso Nikolov utilizes improper neutralization of input during web page generation, leading to a reflected cross-site scripting (XSS) flaw. This vulnerability permits an attacker to insert arbitrary scripts into web pages displayed to users, potentially enabling data theft or session hijacking. The affected versions include all prior to and including 2.3.1. Implementing secure coding practices and validating user input are essential to mitigate this risk.
Affected Version(s)
Event Tickets with Ticket Scanner <= 2.3.1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Le Ngoc Anh (Patchstack Alliance)