SourceCodester Contact Manager with Export to VCF 1.0 index.html contact_name Cross Site Scripting

Hakika vulnerability da aka rarraba a matsayin karshewa an gano a SourceCodester Contact Manager with Export to VCF 1.0. Tabbas, aikin $software_function ne ke da matsala; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburare $software_library, a cikin fayil index.html, a cikin sashi $software_component. Wuro manipulation of the argument contact_name ga Cross Site Scripting. Amfani da CWE wajen bayyana matsala yana kaiwa CWE-79. Lalle, rauni an sanar da shi 08/30/2024. Ana samun bayanin tsaro don saukewa a github.com. Ana kiran wannan rauni da CVE-2024-8337. Ngam yiɗi ka a tuma ndiyam ka internet. Bayani na fasaha ga. Kuma, akwai exploit. Exploit ɗin an bayyana wa jama'a, za a iya amfani da shi. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á yí huɗɗi-na-gaskiya. Za a iya samun exploit a github.com. 0-day ga, an ndiyam a wuro be $0-$5k. If you want to get best quality of vulnerability data, you may have to visit VulDB.

6 Goyarwa · 88 Datenpunkte

FurɗeGargadi 1/5
08/31/2024 15:10
Gargadi 2/5
09/04/2024 04:38
Gargadi 3/5
09/05/2024 03:44
Gargadi 4/5
09/17/2024 10:45
Gargadi 5/5
03/11/2025 17:24
software_vendorSourceCodesterSourceCodesterSourceCodesterSourceCodesterSourceCodester
software_nameContact Manager with Export to VCFContact Manager with Export to VCFContact Manager with Export to VCFContact Manager with Export to VCFContact Manager with Export to VCF
software_version1.01.01.01.01.0
software_fileindex.htmlindex.htmlindex.htmlindex.htmlindex.html
software_argumentcontact_namecontact_namecontact_namecontact_namecontact_name
vulnerability_cweCWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)CWE-79 (Cross Site Scripting)
vulnerability_risk11111
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_uiRRRRR
cvss3_vuldb_sUUUUU
cvss3_vuldb_cNNNNN
cvss3_vuldb_iLLLLL
cvss3_vuldb_aNNNNN
cvss3_vuldb_ePPPPP
cvss3_vuldb_rcRRRRR
exploit_availability11111
exploit_publicity11111
source_cveCVE-2024-8337CVE-2024-8337CVE-2024-8337CVE-2024-8337CVE-2024-8337
cna_responsibleVulDBVulDBVulDBVulDBVulDB
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_ciNNNNN
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiNNNNN
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcURURURURUR
cvss4_vuldb_avNNNNN
cvss4_vuldb_acLLLLL
cvss4_vuldb_vcNNNNN
cvss4_vuldb_viLLLLL
cvss4_vuldb_vaNNNNN
cvss4_vuldb_ePPPPP
cvss2_vuldb_auSSSSS
cvss2_vuldb_rlNDNDNDNDND
cvss3_vuldb_prLLLLL
cvss3_vuldb_rlXXXXX
cvss4_vuldb_atNNNNN
cvss4_vuldb_prLLLLL
cvss4_vuldb_uiNNNNP
cvss4_vuldb_scNNNNN
cvss4_vuldb_siNNNNN
cvss4_vuldb_saNNNNN
cvss2_vuldb_basescore4.04.04.04.04.0
cvss2_vuldb_tempscore3.43.43.43.43.4
cvss3_vuldb_basescore3.53.53.53.53.5
cvss3_vuldb_tempscore3.23.23.23.23.2
cvss3_meta_basescore3.53.54.14.14.1
cvss3_meta_tempscore3.33.34.04.04.0
cvss4_vuldb_bscore5.35.35.35.35.1
cvss4_vuldb_btscore2.12.12.12.12.0
advisory_date1724968800 (08/30/2024)1724968800 (08/30/2024)1724968800 (08/30/2024)1724968800 (08/30/2024)1724968800 (08/30/2024)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k$0-$5k
cve_nvd_summaryA vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
cvss3_cna_avNNNNN
cvss3_cna_acLLLLL
cvss3_cna_prLLLLL
cvss3_cna_uiRRRRR
cvss3_cna_sUUUUU
cvss3_cna_cNNNNN
cvss3_cna_iLLLLL
cvss3_cna_aNNNNN
cvss3_cna_basescore3.53.53.53.53.5
cvss2_cna_avNNNNN
cvss2_cna_acLLLLL
cvss2_cna_auSSSSS
cvss2_cna_ciNNNNN
cvss2_cna_iiPPPPP
cvss2_cna_aiNNNNN
cvss2_cna_basescore44444
cve_nvd_summaryesSe ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse.Se ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse.Se ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse.Se ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse.
cvss3_nvd_avNNN
cvss3_nvd_acLLL
cvss3_nvd_prLLL
cvss3_nvd_uiRRR
cvss3_nvd_sCCC
cvss3_nvd_cLLL
cvss3_nvd_iLLL
cvss3_nvd_aNNN
cvss3_nvd_basescore5.45.45.4
advisory_urlhttps://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.mdhttps://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.md
exploit_urlhttps://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.mdhttps://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.md

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!