CVE-2023-44048

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 27, 2023
Updated: Sep 30, 2023
CWE ID 79

Summary

CVE-2023-44048 is a Cross Site Scripting (XSS) vulnerability affecting the Sourcecodester Expense Tracker App version 1. An attacker can exploit this issue by injecting malicious code through the "add category" feature. Successful exploitation could lead to unauthorized script execution in the context of the affected user, potentially resulting in data theft or session hijacking. Users are advised to upgrade to the latest version of the app or apply relevant patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share