CVE-2024-24494: XSS
Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, readbook, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24494?
CVE-2024-24494 is classified as a high severity vulnerability due to its potential for remote code execution through cross-site scripting.
How do I fix CVE-2024-24494?
To fix CVE-2024-24494, sanitize and validate user inputs in the affected parameters before processing them in add-tracker.php and update-tracker.php.
What software is affected by CVE-2024-24494?
CVE-2024-24494 affects Daily Habit Tracker version 1.0.
Can CVE-2024-24494 be exploited remotely?
Yes, CVE-2024-24494 can be exploited remotely by an attacker to execute arbitrary code.
What parameters are involved in CVE-2024-24494?
The parameters involved in CVE-2024-24494 include day, exercise, pray, read_book, vitamins, laundry, alcohol, and meat.