Severity
5.3MEDIUM
EPSS
0.2%
top 58.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Inventory Page. The manipulation of the argument brand leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
SourceCodester Online Eyewear Shop Inventory Page Master.php cross site scripting2024-11-15
GHSA
GHSA-vr4m-p38h-8h6w: A vulnerability has been found in SourceCodester Online Eyewear Shop 12024-11-15
CVE-2024-11247 (MEDIUM CVSS 5.3) | A vulnerability has been found in S | cvebase.io