Cross Site Scripting Vulnerability in Kashipara Online Furniture Shopping Ecommerce Website's search.php
CVE-2024-4072
Key Information:
- Vendor
Kashipara
- Vendor
- CVE Published:
- 23 April 2024
Badges
What is CVE-2024-4072?
A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as problematic. Affected is an unknown function of the file search.php. The manipulation of the argument txtSearch leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-261798 is the identifier assigned to this vulnerability.
Affected Version(s)
Online Furniture Shopping Ecommerce Website 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
