CVE-2024-33979: Cross-site Scripting in Janobe products
Cross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'q', 'arrival', 'departure' and 'accomodation' parameters in '/index.php'.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33979?
CVE-2024-33979 is classified as a Cross-Site Scripting (XSS) vulnerability which poses a significant security risk.
How do I fix CVE-2024-33979?
To fix CVE-2024-33979, upgrade all affected Janobe products to the latest version that addresses the vulnerability.
What products are affected by CVE-2024-33979?
CVE-2024-33979 affects version 1.0 of Janobe Credit Card, Janobe Debit Card Payment, and Janobe PayPal.
What type of attack is facilitated by CVE-2024-33979?
CVE-2024-33979 allows attackers to conduct Cross-Site Scripting (XSS) attacks by exploiting specially crafted URLs.
What are the potential impacts of CVE-2024-33979?
The potential impacts of CVE-2024-33979 include theft of session cookies and unauthorized access to user sessions.