Vulnerability Description
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpmybackuppro | Phpmybackuppro | 2.3 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerabThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerabThird Party Advisory
FAQ
What is CVE-2024-5414?
CVE-2024-5414 is a vulnerability with a CVSS score of 7.1 (HIGH). A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities co...
How severe is CVE-2024-5414?
CVE-2024-5414 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-5414?
Check the references section above for vendor advisories and patch information. Affected products include: Phpmybackuppro Phpmybackuppro.