Severity
6.1MEDIUMNVD
CNA3.5
EPSS
0.1%
top 80.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 30
Latest updateNov 19

Description

A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnerability affects unknown code of the component New Account Handler. The manipulation of the argument First Name/Last Name with the input alert(1) leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252292.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

5
GHSA
Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries2024-08-27
GHSA
Unlimited number of NTS-KE connections can crash ntpd-rs server2024-06-28
CVEList
SourceCodester Facebook News Feed Like New Account cross site scripting2024-01-30
GHSA
GHSA-pwq2-rpq6-5x8x: A vulnerability has been found in SourceCodester Facebook News Feed Like 12024-01-30
GHSA
encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs2023-10-24

💥Exploits & PoCs

1
Nuclei
Lightdash v0.1024.6 - Server-Side Request Forgery

📋Vendor Advisories

9
Red Hat
kernel: dm cache: fix out-of-bounds access to the dirty bitset when resizing2024-11-19
Red Hat
kernel: smb: client: fix OOBs when building SMB2_IOCTL request2024-11-07
Red Hat
kernel: block: fix integer overflow in BLKSECDISCARD2024-10-21
Red Hat
kernel: Input: MT - limit max slots2024-09-04
Red Hat
kernel: PCI: endpoint: Clean up error handling in vpci_scan_bus()2024-08-21
CVE-2024-1024 — Cross-site Scripting | cvebase