CVE-2024-33976: Cross-site Scripting in Janobe E-Negosyo System
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted JavaScript payload to an authenticated user and partially take over their browser session via 'id' parameter in '/admin/user/index.php'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33976?
CVE-2024-33976 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
How can I mitigate CVE-2024-33976?
Mitigation for CVE-2024-33976 involves ensuring that input validation and output encoding mechanisms are properly implemented in the E-Negosyo System.
Who is affected by CVE-2024-33976?
CVE-2024-33976 affects users of the E-Negosyo System version 1.0.
What kind of attack can be executed using CVE-2024-33976?
An attacker can execute a Cross-Site Scripting attack by sending a crafted JavaScript payload to authenticated users.
Is there a patch available for CVE-2024-33976?
As of now, a specific patch for CVE-2024-33976 has not been publicly disclosed.