CVE-2024-0722

LOW

code-projects Social Networking Site 1.0 - XSS

Title source: llm
STIX 2.1

Description

A vulnerability was found in code-projects Social Networking Site 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file message.php of the component Message Page. The manipulation of the argument Story leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251546 is the identifier assigned to this vulnerability.

References (3)

Core 3
Core References
Permissions Required vdb-entry technical-description
https://vuldb.com/?id.251546
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.251546

Scores

CVSS v3 3.5
EPSS 0.0012
EPSS Percentile 30.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
code-projects/social_networking_site 1.0
Published Jan 19, 2024
Tracked Since Feb 18, 2026