Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-06173
HistoryJan 16, 2024 - 12:00 a.m.

Inventory Management System Cross-Site Scripting Vulnerability

2024-01-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
inventory management system
cross-site scripting
vulnerability
new item creation page
user-supplied data
web script
html
exploitation

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.7%

Inventory Management System is an inventory management system. A cross-site scripting vulnerability exists in Inventory Management System version 1.0, which stems from the lack of effective filtering and escaping of user-supplied data in the parameter new_item in the component New Item Creation Page, and can be exploited by an attacker to inject a carefully crafted payload to execute Any Web script or HTML.

6.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.7%

Related for CNVD-2024-06173