XSS Vulnerability in SourceCodester Packers and Movers Management System
CVE-2024-57522
6.4MEDIUM
Summary
The SourceCodester Packers and Movers Management System v1.0 has a security flaw that allows attackers to exploit Cross Site Scripting (XSS) vulnerabilities in the Users.php file. This vulnerability enables an attacker to inject malicious scripts into the username or name fields during user creation, potentially compromising user data and executing harmful actions within the user's browser. Proper input validation and output encoding mechanisms are essential to mitigate such vulnerabilities.
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved