
Proof-of-concept per CVE-2024-48415: vulnerabilità XSS persistente in itsourcecode Loan Management System v1.0 tramite i campi del profilo del mutuatario. Include vettori di attacco e riferimento OWASP.
Descrizione itsourcecode Loan Management System v1.0 è vulnerabile a Cross Site Scripting (XSS) tramite un payload appositamente predisposto nei parametri lastname, firstname, middlename, address, contact_no, email e tax_id nella funzionalità new borrowers della pagina Borrowers.
Tipo di vulnerabilità: Cross Site Scripting (XSS)
Fornitore del prodotto: itsourcecode
Base del codice del prodotto interessato: https://itsourcecode.com/free-projects/php-project/loan-management-system-project-in-php-with-source-code/ - 1.0
Componente interessato: Loan Management System v1.0
Vettori di attacco:
Riferimento: https://owasp.org/www-community/attacks/xss/