A vulnerability, which was classified as problematic, has been found in SourceCodester FAQ Management System 1.0. Affected by this issue is some unknown functionality of the component Update FAQ. The manipulation of the argument Frequently Asked Question leads to cross site scripting. The attack may be launched remotely. VDB-255386 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/will121351/wenqin.webray.com.cn/blob/main/CVE-project/faq-management-system.md | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.255386 | Permissions Required |
https://vuldb.com/?id.255386 | Third Party Advisory |
https://github.com/will121351/wenqin.webray.com.cn/blob/main/CVE-project/faq-management-system.md | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.255386 | Permissions Required |
https://vuldb.com/?id.255386 | Third Party Advisory |
Configurations
History
31 Dec 2024, 17:42
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:remyandrade:faq_management_system:1.0:*:*:*:*:*:*:* | |
First Time |
Remyandrade
Remyandrade faq Management System |
|
References | () https://github.com/will121351/wenqin.webray.com.cn/blob/main/CVE-project/faq-management-system.md - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.255386 - Permissions Required | |
References | () https://vuldb.com/?id.255386 - Third Party Advisory |
21 Nov 2024, 09:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/will121351/wenqin.webray.com.cn/blob/main/CVE-project/faq-management-system.md - | |
References | () https://vuldb.com/?ctiid.255386 - | |
References | () https://vuldb.com/?id.255386 - |
21 Mar 2024, 02:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 Mar 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-01 17:15
Updated : 2024-12-31 17:42
NVD link : CVE-2024-2071
Mitre link : CVE-2024-2071
CVE.ORG link : CVE-2024-2071
JSON object : View
Products Affected
remyandrade
- faq_management_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')