| Furɗe | Gargadi 1/5 08/31/2024 15:10 | Gargadi 2/5 09/04/2024 04:38 | Gargadi 3/5 09/05/2024 03:44 | Gargadi 4/5 09/17/2024 10:45 | Gargadi 5/5 03/11/2025 17:24 |
|---|
| software_vendor | SourceCodester | SourceCodester | SourceCodester | SourceCodester | SourceCodester |
| software_name | Contact Manager with Export to VCF | Contact Manager with Export to VCF | Contact Manager with Export to VCF | Contact Manager with Export to VCF | Contact Manager with Export to VCF |
| software_version | 1.0 | 1.0 | 1.0 | 1.0 | 1.0 |
| software_file | index.html | index.html | index.html | index.html | index.html |
| software_argument | contact_name | contact_name | contact_name | contact_name | contact_name |
| vulnerability_cwe | CWE-79 (Cross Site Scripting) | CWE-79 (Cross Site Scripting) | CWE-79 (Cross Site Scripting) | CWE-79 (Cross Site Scripting) | CWE-79 (Cross Site Scripting) |
| vulnerability_risk | 1 | 1 | 1 | 1 | 1 |
| cvss3_vuldb_av | N | N | N | N | N |
| cvss3_vuldb_ac | L | L | L | L | L |
| cvss3_vuldb_ui | R | R | R | R | R |
| cvss3_vuldb_s | U | U | U | U | U |
| cvss3_vuldb_c | N | N | N | N | N |
| cvss3_vuldb_i | L | L | L | L | L |
| cvss3_vuldb_a | N | N | N | N | N |
| cvss3_vuldb_e | P | P | P | P | P |
| cvss3_vuldb_rc | R | R | R | R | R |
| exploit_availability | 1 | 1 | 1 | 1 | 1 |
| exploit_publicity | 1 | 1 | 1 | 1 | 1 |
| source_cve | CVE-2024-8337 | CVE-2024-8337 | CVE-2024-8337 | CVE-2024-8337 | CVE-2024-8337 |
| cna_responsible | VulDB | VulDB | VulDB | VulDB | VulDB |
| cvss2_vuldb_av | N | N | N | N | N |
| cvss2_vuldb_ac | L | L | L | L | L |
| cvss2_vuldb_ci | N | N | N | N | N |
| cvss2_vuldb_ii | P | P | P | P | P |
| cvss2_vuldb_ai | N | N | N | N | N |
| cvss2_vuldb_e | POC | POC | POC | POC | POC |
| cvss2_vuldb_rc | UR | UR | UR | UR | UR |
| cvss4_vuldb_av | N | N | N | N | N |
| cvss4_vuldb_ac | L | L | L | L | L |
| cvss4_vuldb_vc | N | N | N | N | N |
| cvss4_vuldb_vi | L | L | L | L | L |
| cvss4_vuldb_va | N | N | N | N | N |
| cvss4_vuldb_e | P | P | P | P | P |
| cvss2_vuldb_au | S | S | S | S | S |
| cvss2_vuldb_rl | ND | ND | ND | ND | ND |
| cvss3_vuldb_pr | L | L | L | L | L |
| cvss3_vuldb_rl | X | X | X | X | X |
| cvss4_vuldb_at | N | N | N | N | N |
| cvss4_vuldb_pr | L | L | L | L | L |
| cvss4_vuldb_ui | N | N | N | N | P |
| cvss4_vuldb_sc | N | N | N | N | N |
| cvss4_vuldb_si | N | N | N | N | N |
| cvss4_vuldb_sa | N | N | N | N | N |
| cvss2_vuldb_basescore | 4.0 | 4.0 | 4.0 | 4.0 | 4.0 |
| cvss2_vuldb_tempscore | 3.4 | 3.4 | 3.4 | 3.4 | 3.4 |
| cvss3_vuldb_basescore | 3.5 | 3.5 | 3.5 | 3.5 | 3.5 |
| cvss3_vuldb_tempscore | 3.2 | 3.2 | 3.2 | 3.2 | 3.2 |
| cvss3_meta_basescore | 3.5 | 3.5 | 4.1 | 4.1 | 4.1 |
| cvss3_meta_tempscore | 3.3 | 3.3 | 4.0 | 4.0 | 4.0 |
| cvss4_vuldb_bscore | 5.3 | 5.3 | 5.3 | 5.3 | 5.1 |
| cvss4_vuldb_btscore | 2.1 | 2.1 | 2.1 | 2.1 | 2.0 |
| advisory_date | 1724968800 (08/30/2024) | 1724968800 (08/30/2024) | 1724968800 (08/30/2024) | 1724968800 (08/30/2024) | 1724968800 (08/30/2024) |
| price_0day | $0-$5k | $0-$5k | $0-$5k | $0-$5k | $0-$5k |
| cve_nvd_summary | A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some unknown functionality of the file index.html. The manipulation of the argument contact_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
| cvss3_cna_av | N | N | N | N | N |
| cvss3_cna_ac | L | L | L | L | L |
| cvss3_cna_pr | L | L | L | L | L |
| cvss3_cna_ui | R | R | R | R | R |
| cvss3_cna_s | U | U | U | U | U |
| cvss3_cna_c | N | N | N | N | N |
| cvss3_cna_i | L | L | L | L | L |
| cvss3_cna_a | N | N | N | N | N |
| cvss3_cna_basescore | 3.5 | 3.5 | 3.5 | 3.5 | 3.5 |
| cvss2_cna_av | N | N | N | N | N |
| cvss2_cna_ac | L | L | L | L | L |
| cvss2_cna_au | S | S | S | S | S |
| cvss2_cna_ci | N | N | N | N | N |
| cvss2_cna_ii | P | P | P | P | P |
| cvss2_cna_ai | N | N | N | N | N |
| cvss2_cna_basescore | 4 | 4 | 4 | 4 | 4 |
| cve_nvd_summaryes | | Se ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse. | Se ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse. | Se ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse. | Se ha encontrado una vulnerabilidad clasificada como problemática en SourceCodester Contact Manager con Export to VCF 1.0. Este problema afecta a algunas funciones desconocidas del archivo index.html. La manipulación del argumento contact_name provoca cross site scripting. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse. |
| cvss3_nvd_av | | | N | N | N |
| cvss3_nvd_ac | | | L | L | L |
| cvss3_nvd_pr | | | L | L | L |
| cvss3_nvd_ui | | | R | R | R |
| cvss3_nvd_s | | | C | C | C |
| cvss3_nvd_c | | | L | L | L |
| cvss3_nvd_i | | | L | L | L |
| cvss3_nvd_a | | | N | N | N |
| cvss3_nvd_basescore | | | 5.4 | 5.4 | 5.4 |
| advisory_url | | | | https://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.md | https://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.md |
| exploit_url | | | | https://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.md | https://github.com/gurudattch/CVEs/blob/main/SourceCodester-Contact-managemet-system-Stored-XSS.md |