CVE-2024-0423
Description
A vulnerability was found in CodeAstro Online Food Ordering System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file dishes.php. The manipulation of the argument res_id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250442 is the identifier assigned to this vulnerability.
- CVSS Version 3.1
- CVSS Version 3.0
- CVSS Version 2.0
nvd
CVE ID: CVE-2024-0423
Base Score: 5.4
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Impact Score: 2.7
Exploitability Score: 2.3
vuldb
CVE ID: CVE-2024-0423
Base Score: 3.5
Base Severity: LOW
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Impact Score: 1.4
Exploitability Score: 2.1
vuldb
CVE ID: CVE-2024-0423
Base Score: 3.5
Base Severity: LOW
Vector String:CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
vuldb
CVE ID: CVE-2024-0423
Base Score: 4.0
Base Severity: MEDIUM
Vector String:AV:N/AC:L/Au:S/C:N/I:P/A:N