CVE-2024-11995: code-projects Farmacia pagamento.php cross site scripting
A vulnerability has been found in code-projects Farmacia 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /pagamento.php. The manipulation of the argument total leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11995?
CVE-2024-11995 is classified as a problematic vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-11995?
To fix CVE-2024-11995, ensure proper input validation and sanitization for the 'total' argument in the /pagamento.php file.
What systems are affected by CVE-2024-11995?
CVE-2024-11995 affects the Anisha Farmacia version 1.0 software.
What type of vulnerability is CVE-2024-11995?
CVE-2024-11995 is a cross-site scripting (XSS) vulnerability.
Can CVE-2024-11995 be exploited remotely?
Yes, CVE-2024-11995 can be exploited remotely by manipulating the total argument.