VulnerabilityModified
CVE-2024-24135
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
MEDIUM 6.1EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- remyandrade/product inventory with export to excel
- Source
- cve@mitre.org
References
- https://github.com/BurakSevben/2024_Product_Inventory_with_Export_to_Excel_XSS/Exploit, Third Party Advisory
- https://github.com/BurakSevben/2024_Product_Inventory_with_Export_to_Excel_XSS/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.