CVE-2024-10198
Code-projects
CVE-2024-10198 exposes a cross-site scripting (XSS) vulnerability in Pharmacy Management System 1.0, specifically affecting the '/manage_customer.php' component. Attackers can remotely inject malicious scripts by manipulating the 'suppliers_name' or 'address' arguments within the Manage Customer Page, potentially compromising user data and system integrity. The relatively low CVSS score of 4.8 might underestimate the risk, however, the SVRS score of 49 indicates a moderate threat level. Although not immediately critical (SVRS > 80), the public availability of an exploit makes this vulnerability a significant concern that warrants patching. This vulnerability could allow attackers to steal sensitive information or perform unauthorized actions on behalf of legitimate users. Given the 'In The Wild' tag, immediate investigation and patching are advised to prevent potential exploitation of this pharmacy system flaw. Ignoring this could lead to data breaches and damage to the reputation of the affected systems.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.