CVE-2023-24194: XSS
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24194?
The severity of CVE-2023-24194 is medium with a CVSS score of 6.1.
How does the cross-site scripting (XSS) vulnerability in CVE-2023-24194 work?
The cross-site scripting (XSS) vulnerability in CVE-2023-24194 occurs when the 'page' parameter in navbar.php is not properly validated or sanitized, allowing an attacker to inject malicious scripts into the website.
What is the affected software for CVE-2023-24194?
The affected software for CVE-2023-24194 is Online Food Ordering System version 2.0.
Is there a fix available for CVE-2023-24194?
Yes, it is recommended to update to a patched version of Online Food Ordering System to fix the cross-site scripting (XSS) vulnerability.
Where can I find more information about CVE-2023-24194?
You can find more information about CVE-2023-24194 at the following references: [GitHub](https://github.com/xiumulty/CVE/blob/main/Online%20Food%20Ordering%20System%20v2/xss%20in%20navbar.php.md) and [Source Codester](https://www.sourcecodester.com/php/16022/online-food-ordering-system-v2-using-php8-and-mysql-free-source-code.html).