Cross-site Scripting Vulnerability in Kortex Lite Advocate Office Management System 1.0
CVE-2024-7683
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 12 August 2024
Badges
Summary
A cross-site scripting vulnerability is present in the addcase_stage.php file of SourceCodester's Kortex Lite Advocate Office Management System version 1.0. This vulnerability arises due to improper handling of the 'cname' argument, which can be manipulated by attackers to inject malicious scripts. The nature of this vulnerability allows for remote exploitation, making it imperative for users and organizations to implement necessary security measures to safeguard their systems against potential attacks.
Affected Version(s)
Kortex Lite Advocate Office Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved