SiAdmin 1.1 Vulnerability: XSS via /show.php Query Parameter
CVE-2024-4993

6.3MEDIUM

Key Information:

Vendor

Siadmin

Status
Vendor
CVE Published:
16 May 2024

What is CVE-2024-4993?

Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and thereby steal their cookie session credentials.

Affected Version(s)

SiAdmin 1.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafael Pedrero
.