CVE-2024-11587: idcCMS classProvCity.php GetCityOptionJs cross site scripting
A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProvCity.php. The manipulation of the argument idName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11587?
CVE-2024-11587 has been classified as problematic due to its potential for exploitation.
How do I fix CVE-2024-11587?
To mitigate CVE-2024-11587, you should validate and sanitize the input in the GetCityOptionJs function to prevent cross-site scripting.
What is the affected software for CVE-2024-11587?
CVE-2024-11587 affects idcCMS version 1.60.
Can CVE-2024-11587 be exploited remotely?
Yes, CVE-2024-11587 can be exploited remotely through the manipulation of the idName argument.
What type of vulnerability is CVE-2024-11587?
CVE-2024-11587 is a cross-site scripting (XSS) vulnerability.