CVE-2024-33977: Cross-site Scripting in Janobe E-Negosyo System
Published Aug 6, 2024
·Updated
Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'view' parameter in /admin/orders/index.php'.
Affected Software
1 affected component
Janobe Young Entrepreneur E-negosyo System=1.0
Remediation
Information
There is no reported solution at this time.
Event History
Aug 6, 2024
CVE Published
via MITRE·10:58 AM
Data Sourced
via MITRE·10:58 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-33977?
CVE-2024-33977 is classified as a Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2024-33977?
To fix CVE-2024-33977, upgrade to a patched version of the E-Negosyo System released by the vendor.
3
Which versions are affected by CVE-2024-33977?
CVE-2024-33977 affects version 1.0 of the E-Negosyo System.
4
What exploitation method is used in CVE-2024-33977?
CVE-2024-33977 can be exploited by an attacker sending a specially crafted URL to obtain a victim's session cookie details.
5
What component is vulnerable in CVE-2024-33977?
The vulnerable component in CVE-2024-33977 is located at the '/admin/orders/index.php' endpoint.