CVE-2024-2997

LOW

Bdtask Multi-Store Inventory Management System <20240320 - XSS

Title source: llm

Description

A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument Category Name/Model Name/Brand Name/Unit Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258199. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (5)

nomisec SCANNER 11 stars
by lfillaz · poc
https://github.com/lfillaz/CVE-2024-2997
nomisec SCANNER 1 stars
by NullEssa · poc
https://github.com/NullEssa/CVE-2024-2997
nomisec WORKING POC 1 stars
by lfilharv · poc
https://github.com/lfilharv/CVE-2024-2997
nomisec SCANNER
by 0xUho · poc
https://github.com/0xUho/CVE-2024-2997
nomisec SCANNER
by o9-9 · poc
https://github.com/o9-9/CVE-2024-2997

Scores

CVSS v3 2.4
EPSS 0.0579
EPSS Percentile 90.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
bdtask/multi_store_inventory_management_system < 20240320
Published Mar 27, 2024
Tracked Since Feb 18, 2026