CVE-2024-3428: SourceCodester Online Courseware edit.php cross site scripting
A vulnerability has been found in SourceCodester Online Courseware 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit.php. The manipulation of the argument id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259600.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3428?
CVE-2024-3428 is classified as a problematic vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2024-3428?
To fix CVE-2024-3428, you should sanitize and validate the input parameters in the edit.php file to prevent cross-site scripting.
What type of vulnerability is CVE-2024-3428?
CVE-2024-3428 is a cross-site scripting (XSS) vulnerability that can be exploited remotely.
Which software versions are affected by CVE-2024-3428?
CVE-2024-3428 impacts SourceCodester Online Courseware version 1.0.
Can CVE-2024-3428 be exploited without authentication?
Yes, CVE-2024-3428 can be exploited remotely, meaning that authentication is not required to trigger the vulnerability.