CVE-2024-24050: XSS
Published Mar 20, 2024
·Updated
Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.
Affected Software
2 affected components
Sourcecodester Workout Journal App
Remyandrade Workout Journal App=1.0
Event History
Mar 20, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24050?
CVE-2024-24050 is considered a critical Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-24050?
To fix CVE-2024-24050, validate and sanitize user inputs for the firstname and lastname parameters in /add-user.php.
3
What kind of attack can exploit CVE-2024-24050?
CVE-2024-24050 can be exploited through Cross Site Scripting (XSS) allowing attackers to run arbitrary code.
4
Which application is affected by CVE-2024-24050?
CVE-2024-24050 affects Sourcecodester Workout Journal App version 1.0.
5
What is the impact of exploiting CVE-2024-24050?
Exploiting CVE-2024-24050 can lead to unauthorized access and manipulation of user data.