CVE-2024-9320

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Sep 29, 2024
Updated: Oct 1, 2024
CWE ID 79

Summary

CVE-2024-9320 is a newly disclosed vulnerability affecting the SourceCodester Online Timesheet App 1.0. This issue lies in the code of the "/endpoint/add-timesheet.php" component's Add Timesheet Form, specifically the day/task argument. The vulnerability enables an attacker to inject cross-site scripting (XSS) code, potentially allowing them to steal sensitive user data or take control of the user's session. The exploit can be executed remotely, making it a significant threat to users of this application. The vulnerability has been made public, increasing the risk of widespread exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share