CVE-2024-1103: CodeAstro Real Estate Management System Feedback Form profile.php cross site scripting
A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input <img src=x onerror=alert(document.cookie)> leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252458 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1103?
CVE-2024-1103 has been rated as problematic.
What component of CodeAstro Real Estate Management System is affected by CVE-2024-1103?
The affected component is the Feedback Form functionality in the file profile.php.
How can we exploit CVE-2024-1103?
CVE-2024-1103 can be exploited by manipulating the input argument 'Your Feedback' with malicious content.
How do I fix CVE-2024-1103?
To fix CVE-2024-1103, ensure proper input validation and sanitization in the affected Feedback Form.
What version of CodeAstro Real Estate Management System is affected by CVE-2024-1103?
CVE-2024-1103 affects version 1.0 of CodeAstro Real Estate Management System.