Cross Site Scripting Vulnerability in SourceCodester Online Eyewear Shop
CVE-2024-9906
Key Information:
- Vendor
- Sourcecodester
- Status
- Vendor
- CVE Published:
- 13 October 2024
Badges
Summary
An undisclosed function within the SourceCodester Online Eyewear Shop 1.0 is vulnerable to cross site scripting through the argument manipulation in the URL. Specifically, the endpoint /admin/?page=inventory/view_inventory&id=2 is susceptible to this exploit, which could allow remote attackers to execute arbitrary scripts in the context of a user's browser. This vulnerability poses a risk of exposing sensitive user information and modifying the way the web application behaves, potentially leading to phishing or other malicious activities.
Affected Version(s)
Online Eyewear Shop 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved