Sploitus

CVE-2024-23879

1 known exploit for CVE-2024-23879

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/statemodify.php, in the description parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.

Affected products
Cups Easy
Ajaysharma Cups Easy
= 1.0
CVSS 3.1
8.2 HIGH
EPSS
0.4% (33th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2024-01-26
CVE-2024-23879 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2024-23879

Proof-of-concept code and exploit modules indexed by Sploitus