CVE-2024-1010

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 29, 2024
Updated: May 17, 2024
CWE ID 79

Summary

CVE-2024-1010 is a newly discovered vulnerability affecting the SourceCodester Employee Management System 1.0. The issue lies within the file edit-profile.php, where manipulation of the arguments fullname, phone, date of birth, address, or date of appointment can trigger a cross-site scripting (XSS) attack. This vulnerability poses a significant risk as it can be exploited remotely. The associated identifier for this security flaw is VDB-252279.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share