First published: Mon Aug 26 2024(Updated: )
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lopalopa Music Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42790 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2024-42790, validate and sanitize the user input for the "page" parameter to prevent XSS attacks.
CVE-2024-42790 affects Kashipara Music Management System version 1.0.
Yes, CVE-2024-42790 can lead to data theft as it allows attackers to execute arbitrary code.
The vulnerability CVE-2024-42790 was identified in the Kashipara Music Management System developed by Lopalopa.