First published: Wed Sep 09 2020(Updated: )
A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stock Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24198 is classified as a high-severity vulnerability due to its potential for persistent cross-site scripting attacks.
To fix CVE-2020-24198, update the Stock Management System to a version that has patched this vulnerability.
Exploiting CVE-2020-24198 allows attackers to inject arbitrary web scripts or HTML, potentially leading to data theft or session hijacking.
Yes, CVE-2020-24198 can be exploited remotely by attackers without local access to the system.
CVE-2020-24198 specifically affects Sourcecodester Stock Management System version 1.0.