CVE-2024-10746
Phpgurukul
CVE-2024-10746: Cross-Site Scripting vulnerability in PHPGurukul Online Shopping Portal 2.0. Remotely exploitable XSS flaw in /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php, allows attackers to inject malicious scripts via the 'scripts' argument. While the CVSS score is 6.1, the SOCRadar Vulnerability Risk Score (SVRS) is 58, indicating a moderate risk but should still be addressed. Public exploit availability increases the potential for exploitation. The vulnerability arises from improper input sanitization, leading to execution of arbitrary JavaScript code in a user's browser. If exploited, attackers could steal sensitive information or perform actions on behalf of the victim. It's a security risk because it allows remote code execution, potentially compromising user accounts and data. Immediate patching or mitigation is recommended to reduce the attack surface.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.