Cross-site Scripting Vulnerability in Toll Tax Management System by Sourcecodester
CVE-2024-51032

5.4MEDIUM

Key Information:

Vendor

Oretnom23

Vendor
CVE Published:
8 November 2024

What is CVE-2024-51032?

The Toll Tax Management System by Sourcecodester suffers from a Cross-site Scripting (XSS) vulnerability in the manage_recipient.php script. This security flaw permits remote authenticated users to inject arbitrary web scripts through the 'owner' input field. Exploiting this vulnerability could allow attackers to execute malicious scripts in the context of users' browsers, potentially compromising sensitive information and disrupting the target application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.