Vulnerability Description
Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Douco | Douphp | 1.7_20231203 |
Related Weaknesses (CWE)
References
- https://github.com/Arykon/cve/blob/main/douphp.pdfExploitThird Party Advisory
- https://www.douphp.com/Product
- https://github.com/Arykon/cve/blob/main/douphp.pdfExploitThird Party Advisory
FAQ
What is CVE-2024-57599?
CVE-2024-57599 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cross Site Scripting vulnerability in DouPHP v.1.8 Release 20231203 allows attackers to execute arbitrary code via a crafted payload injected into the description parameter in /admin/article.php
How severe is CVE-2024-57599?
CVE-2024-57599 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57599?
Check the references section above for vendor advisories and patch information. Affected products include: Douco Douphp.