Cross Site Scripting in SourceCodester Complaints Report Management System
CVE-2024-7200
5.4MEDIUM
What is CVE-2024-7200?
A cross site scripting vulnerability has been identified in SourceCodester's Complaints Report Management System version 1.0. The issue arises from improper handling of user input in the /admin/ajax.php?action=save_settings file, allowing attackers to manipulate the argument name. This vulnerability may enable remote attackers to execute arbitrary scripts in the context of a user’s session, posing a significant risk to user data and application integrity. The exploit has been made publicly known, underscoring the urgent need for affected users to implement the necessary security measures.