CVE-2024-33302: XSS
Published May 2, 2024
·Updated
SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users.
Affected Software
2 affected components
Sourcecodester Product Show Room<1.0
oretnom23 Product Show Room Site=1.0
Event History
May 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33302?
CVE-2024-33302 has a medium severity rating due to its potential for exploitation via Cross Site Scripting.
2
How do I fix CVE-2024-33302?
To fix CVE-2024-33302, update SourceCodester Product Show Room to a version later than 1.0 that addresses the XSS vulnerability.
3
What can an attacker do with CVE-2024-33302?
An attacker exploiting CVE-2024-33302 can inject malicious scripts that execute in users' browsers, potentially compromising user data.
4
Is CVE-2024-33302 exploitable in version 1.0 of the software?
Yes, CVE-2024-33302 is exploitable in version 1.0 of SourceCodester Product Show Room.
5
Who is affected by CVE-2024-33302?
All users of SourceCodester Product Show Room version 1.0 and below are affected by CVE-2024-33302.