CVE-2024-1919

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Feb 27, 2024
Updated: Dec 18, 2024
CWE ID 79

Summary

CVE-2024-1919 is a newly disclosed vulnerability affecting the SourceCodester Online Job Portal 1.0. Specifically, it lies within the Manage Walkin Page component and the file /Employer/ManageWalkin.php. The issue arises from a mishandled user input, more specifically the Job Title argument, which results in cross-site scripting (XSS). An attacker can exploit this remotely, potentially injecting malicious scripts into a victim's web browser. Given that the exploit has been made public, it is essential to apply necessary patches or workarounds without delay to safeguard systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share