CVE-2024-25868: XSS
Published Feb 28, 2024
·Updated
A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType parameter in the addtype.php component.
Affected Software
2 affected components
Codeastro Membership Management System
Codeastro Membership Management System=1.0
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25868?
CVE-2024-25868 is categorized as a high severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-25868?
To fix CVE-2024-25868, sanitize and validate user input for the membershipType parameter in the add_type.php component.
3
Who is affected by CVE-2024-25868?
CVE-2024-25868 affects users of CodeAstro Membership Management System version 1.0.
4
What kind of attacks can be executed with CVE-2024-25868?
An attacker can execute arbitrary code via crafted input in the membershipType parameter due to CVE-2024-25868.
5
Is CVE-2024-25868 a remote vulnerability?
Yes, CVE-2024-25868 is a remote vulnerability that can be exploited by attackers over the network.