Showing 2 vulnerabilities on this page for daily_habit_tracker

Signals CISA KEV Ransomware Nuclei
remyandrade vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

SourceCodester Daily Habit Tracker update-tracker.php cross site scripting

A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/update-tracker.php. The manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255391.

CWE-79Mar 1, 2024
CVSS3.5v3.1EPSS0.536%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Daily Habit Tracker 1.0 - Broken Access Control

An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

CWE-284CWE-287Feb 8, 2024
CVSS9.8v3.1EPSS19.5%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX