CVE-2024-7749: SourceCodester Accounts Manager App add-account.php cross site scripting
Published Aug 13, 2024
·Updated
A vulnerability, which was classified as problematic, was found in SourceCodester Accounts Manager App 1.0. Affected is an unknown function of the file /endpoint/add-account.php. The manipulation of the argument accountname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Remyandrade Accounts Manager App=1.0
Event History
Aug 13, 2024
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-7749?
The severity of CVE-2024-7749 is classified as problematic.
2
How do I fix CVE-2024-7749?
To fix CVE-2024-7749, sanitize user input in the account_name parameter to prevent cross-site scripting.
3
What software is affected by CVE-2024-7749?
CVE-2024-7749 affects SourceCodester Accounts Manager App version 1.0.
4
What type of vulnerability is CVE-2024-7749?
CVE-2024-7749 is a cross-site scripting (XSS) vulnerability.
5
Where is the vulnerability located in CVE-2024-7749?
The vulnerability in CVE-2024-7749 is located in the file /endpoint/add-account.php.