CVE-2024-23879
A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/statemodify.php, in the description parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
- Affected products
- Cups Easy
- Ajaysharma Cups Easy
- = 1.0
- CVSS 3.1
- 8.2 HIGH
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2024-01-26
CVE-2024-23879 at NVD
1 known exploit for CVE-2024-23879
Proof-of-concept code and exploit modules indexed by Sploitus