CRUD Creator Vulnerability Exposes Sensitive Data to Cross-Site Scripting
CVE-2024-8562

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 September 2024

Summary

A vulnerability has been identified in SourceCodester PHP CRUD 1.0, specifically in the functionality of the file /endpoint/Add.php. The manipulation of the user input parameters first_name, middle_name, and last_name can lead to cross site scripting (XSS). This issue allows attackers to execute malicious scripts in the context of the user's browser, potentially compromising sensitive information and session identifiers. The publicly disclosed details highlight the necessity for immediate action to safeguard against possible exploitation.

Affected Version(s)

PHP CRUD 1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.