CRUD Creator Vulnerability Exposes Sensitive Data to Cross-Site Scripting
CVE-2024-8562
6.1MEDIUM
Summary
A vulnerability has been identified in SourceCodester PHP CRUD 1.0, specifically in the functionality of the file /endpoint/Add.php. The manipulation of the user input parameters first_name, middle_name, and last_name can lead to cross site scripting (XSS). This issue allows attackers to execute malicious scripts in the context of the user's browser, potentially compromising sensitive information and session identifiers. The publicly disclosed details highlight the necessity for immediate action to safeguard against possible exploitation.
Affected Version(s)
PHP CRUD 1.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved