CVE-2024-5385
CVSS 2.0 Score 3.3 of 10 (low)
Details
Summary
CVE-2024-5385 is a newly identified vulnerability affecting the oretnom23 Online Car Wash Booking System version 1.0. This issue is classified as problematic, as it allows for cross-site scripting (XSS) attacks. Specifically, an attacker can manipulate the argument "First Name/Last Name" with the input "<script>confirm (document.cookie)</script>" during the processing of the file "/admin/?page=user/list". This vulnerability can be exploited remotely, potentially leading to unauthorized access to user cookies. The associated identifier for this vulnerability is VDB-266303.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.