XSS Vulnerability in SourceCodester Packers and Movers Management System
CVE-2024-57522

6.4MEDIUM

Key Information:

Vendor
CVE Published:
3 February 2025

Summary

The SourceCodester Packers and Movers Management System v1.0 has a security flaw that allows attackers to exploit Cross Site Scripting (XSS) vulnerabilities in the Users.php file. This vulnerability enables an attacker to inject malicious scripts into the username or name fields during user creation, potentially compromising user data and executing harmful actions within the user's browser. Proper input validation and output encoding mechanisms are essential to mitigate such vulnerabilities.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.