CVE-2024-5385

CVSS 2.0 Score 3.3 of 10 (low)

Details

Published May 27, 2024
Updated: May 28, 2024
CWE ID 79

Summary

CVE-2024-5385 is a newly identified vulnerability affecting the oretnom23 Online Car Wash Booking System version 1.0. This issue is classified as problematic, as it allows for cross-site scripting (XSS) attacks. Specifically, an attacker can manipulate the argument "First Name/Last Name" with the input "<script>confirm (document.cookie)</script>" during the processing of the file "/admin/?page=user/list". This vulnerability can be exploited remotely, potentially leading to unauthorized access to user cookies. The associated identifier for this vulnerability is VDB-266303.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share