CVE-2024-57326

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1.0. The vulnerability allows an attacker to execute arbitrary JavaScript code in the browser via unsanitized input passed through the search parameter.
References
Link Resource
https://github.com/fatihtuzunn/CVEs/tree/main/CVE-2024-57326 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:online_pizza_delivery_system_project:online_pizza_delivery_system:1.0:*:*:*:*:*:*:*

History

27 Jun 2025, 19:39

Type Values Removed Values Added
First Time Online Pizza Delivery System Project
Online Pizza Delivery System Project online Pizza Delivery System
CPE cpe:2.3:a:online_pizza_delivery_system_project:online_pizza_delivery_system:1.0:*:*:*:*:*:*:*
References () https://github.com/fatihtuzunn/CVEs/tree/main/CVE-2024-57326 - () https://github.com/fatihtuzunn/CVEs/tree/main/CVE-2024-57326 - Exploit, Third Party Advisory

24 Jan 2025, 22:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
Summary
  • (es) Existe una vulnerabilidad Cross-Site Scripting (XSS) Reflejado en el archivo search.php de Online Pizza Delivery System 1.0. La vulnerabilidad permite a un atacante ejecutar código JavaScript arbitrario en el navegador a través de la entrada no desinfectada que se pasa a través del parámetro de búsqueda.

23 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-23 22:15

Updated : 2025-06-27 19:39


NVD link : CVE-2024-57326

Mitre link : CVE-2024-57326

CVE.ORG link : CVE-2024-57326


JSON object : View

Products Affected

online_pizza_delivery_system_project

  • online_pizza_delivery_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')