CVE-2024-46077

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 7, 2024
CWE ID 79

Summary

CVE-2024-46077: Itsourcecode's Online Tours and Travels Management System version 1.0 harbors a Cross-Site Scripting (XSS) vulnerability. Attackers can exploit this flaw by injecting malicious code through specific parameters, including val-username, val-email, val-suggestions, val-digits, and state_name, in the travellers.php file. Successful attacks may result in unauthorized access to user sessions or the theft of sensitive information. Users are urged to upgrade to a patched version or employ input validation and output encoding techniques to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share