2024-07-14 02:06:08 +00:00

97 lines
3.3 KiB
JSON

{
"id": "CVE-2024-3614",
"sourceIdentifier": "cna@vuldb.com",
"published": "2024-04-11T02:15:46.990",
"lastModified": "2024-05-17T02:40:01.707",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability classified as problematic has been found in SourceCodester Warehouse Management System 1.0. This affects an unknown part of the file customer.php. The manipulation of the argument nama_customer/alamat_customer/notelp_customer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-260271."
},
{
"lang": "es",
"value": "Se ha encontrado una vulnerabilidad en SourceCodester Warehouse Management System 1.0 y clasificada como problem\u00e1tica. Una parte desconocida del archivo customer.php afecta a esta vulnerabilidad. La manipulaci\u00f3n del argumento nama_customer/alamat_customer/notelp_customer conduce a cross-site scripting. Es posible iniciar el ataque de forma remota. El exploit ha sido divulgado al p\u00fablico y puede utilizarse. El identificador asociado de esta vulnerabilidad es VDB-260271."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 3.5,
"baseSeverity": "LOW"
},
"exploitabilityScore": 2.1,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "cna@vuldb.com",
"type": "Secondary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "cna@vuldb.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://github.com/fubxx/CVE/blob/main/WarehouseManagementSystemXSS3.md",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?ctiid.260271",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?id.260271",
"source": "cna@vuldb.com"
},
{
"url": "https://vuldb.com/?submit.312703",
"source": "cna@vuldb.com"
}
]
}