First published: Mon Jan 29 2024(Updated: )
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rems Product Inventory | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24135 has a moderate severity level due to its potential for exploitation through XSS attacks.
To fix CVE-2024-24135, validate and sanitize user input in the 'Add Product' section to prevent XSS vulnerabilities.
CVE-2024-24135 is associated with Cross-Site Scripting (XSS) attacks, which can lead to unauthorized actions on behalf of users.
Only version 1.0 of Sourcecodester Product Inventory with Export to Excel is affected by CVE-2024-24135.
The 'Product Name' and 'Product Code' fields in the 'Add Product' section are vulnerable in CVE-2024-24135.