cve/2024/CVE-2024-33978.md
2024-08-07 19:02:05 +00:00

840 B

CVE-2024-33978

Description

Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session cookie details via 'category' parameter in '/index.php'.

POC

Reference

No PoCs from references.

Github