Vulnerability Description
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmybackuppro | Phpmybackuppro | 2.3 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerabThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerabThird Party Advisory
FAQ
What is CVE-2024-5413?
CVE-2024-5413 is a vulnerability with a CVSS score of 7.1 (HIGH). A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities cou...
How severe is CVE-2024-5413?
CVE-2024-5413 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5413?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmybackuppro Phpmybackuppro.