CVE-2024-0423: CodeAstro Online Food Ordering System dishes.php cross site scripting
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file dishes.php. The manipulation of the argument resid leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250442 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0423?
CVE-2024-0423 has been rated as problematic.
What functionality is affected by CVE-2024-0423?
The vulnerability affects the unknown functionality of the file dishes.php.
What type of vulnerability is CVE-2024-0423?
CVE-2024-0423 is a cross site scripting vulnerability.
Can CVE-2024-0423 be exploited remotely?
Yes, the exploitation of CVE-2024-0423 can be launched remotely.
How do I fix CVE-2024-0423?
Patching the code handling the res_id argument in dishes.php is recommended to mitigate CVE-2024-0423.