NA

CVE-2024-23879

Published: 26/01/2024 Updated: 15/02/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/statemodify.php, in the description parameter. Exploitation of this vulnerability could allow a remote malicious user to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ajaysharma cups easy 1.0

Github Repositories

Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)

CVE-2024-23897 Nuclei Template For Exploit CVE-2024-23897 This template serves as a crucial warning to all users if the CVE-2024-23897 local file vulnerability is detected within your system, it is imperative to take immediate action and patch your systems without delay This vulnerability poses a significant risk to the security and integrity of your system, potentially all