CVE-2024-2146: SourceCodester Online Mobile Management Store ?p=products cross site scripting
A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /?p=products. The manipulation of the argument search leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255499.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2146?
CVE-2024-2146 has been declared as a problematic vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-2146?
To fix CVE-2024-2146, ensure input validation and sanitization on the 'search' parameter in the affected /?p=products functionality.
What are the consequences of CVE-2024-2146?
Exploitation of CVE-2024-2146 can lead to unauthorized access and manipulation of user data through cross-site scripting.
Which software is affected by CVE-2024-2146?
CVE-2024-2146 affects SourceCodester Online Mobile Management Store version 1.0.
How can I determine if my system is vulnerable to CVE-2024-2146?
You can determine vulnerability to CVE-2024-2146 by checking if the application version is 1.0 and if it contains the /?p=products functionality.