CVE-2024-11247: SourceCodester Online Eyewear Shop Inventory Page Master.php cross site scripting
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=saveproduct of the component Inventory Page. The manipulation of the argument brand leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11247?
CVE-2024-11247 is classified as a problematic vulnerability due to its impact on the inventory management functionality.
How do I fix CVE-2024-11247?
To resolve CVE-2024-11247, ensure that you are using the latest version of SourceCodester Online Eyewear Shop and apply any available security patches.
Which component is affected by CVE-2024-11247?
CVE-2024-11247 affects the inventory page functionality of the file /oews/classes/Master.php?f=save_product.
What version of SourceCodester Online Eyewear Shop is vulnerable to CVE-2024-11247?
Only version 1.0 of SourceCodester Online Eyewear Shop is affected by CVE-2024-11247.
What types of attacks could exploit CVE-2024-11247?
CVE-2024-11247 could potentially be exploited for unauthorized access or manipulation of product data through the inventory page.