vendor:
E-INSUARANCE
by:
Sandeep Vishwakarma
4.1
CVSS
MEDIUM
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: E-INSUARANCE
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: NO
Related CWE: CVE-2024-29411
CPE: a:sourcecodester:e-insuarance:1.0
Platforms Tested: Windows 10
2024
E-INSUARANCE v1.0 – Stored Cross Site Scripting (XSS)
E-INSUARANCE v1.0 is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can inject malicious code into the Firstname and Lastname parameters in the profile component, allowing them to execute arbitrary scripts.
Mitigation:
To mitigate this vulnerability, sanitize user input by encoding or filtering special characters to prevent script injection.