CVE-2024-11997: code-projects Farmacia vendas.php cross site scripting
A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file /vendas.php. The manipulation of the argument notaFiscal leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11997?
CVE-2024-11997 is classified as problematic, indicating it poses a significant risk.
How do I fix CVE-2024-11997?
To remediate CVE-2024-11997, ensure proper sanitization and validation of user inputs in the notaFiscal argument within vendas.php.
What type of vulnerability is CVE-2024-11997?
CVE-2024-11997 is a Cross-Site Scripting (XSS) vulnerability.
Can CVE-2024-11997 be exploited remotely?
Yes, CVE-2024-11997 can be exploited remotely by manipulating the notaFiscal argument.
Which software version is affected by CVE-2024-11997?
CVE-2024-11997 affects version 1.0 of Anisha Farmacia.