CVE-2024-2145

Severity
6.1MEDIUM
EPSS
0.2%
top 59.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 3

Description

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/update-tracker.php. The manipulation of the argument firstname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255498 is the identifier assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:NExploitability: 2.1 | Impact: 1.4

🔴Vulnerability Details

2
CVEList
SourceCodester Online Mobile Management Store update-tracker.php cross site scripting2024-03-03
GHSA
GHSA-969w-4f3g-v986: A vulnerability was found in SourceCodester Online Mobile Management Store 12024-03-03
CVE-2024-2145 (MEDIUM CVSS 6.1) | A vulnerability was found in Source | cvebase.io