First published: Sat Aug 31 2024(Updated: )
A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit of the component Update My Profile Page. The manipulation of the argument fname/lname/email with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pharmacy Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8366 has been classified as problematic.
To fix CVE-2024-8366, update the Pharmacy Management System to the latest version or apply the recommended patches.
CVE-2024-8366 affects the Update My Profile Page located in the /index.php?id=userProfileEdit file.
The vulnerability allows manipulation of the arguments fname, lname, and email in the user profile edit process.
Yes, CVE-2024-8366 specifically affects version 1.0 of the code-projects Pharmacy Management System.