{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-4072","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-04-23T13:40:49.172Z","datePublished":"2024-04-23T22:31:04.805Z","dateUpdated":"2024-08-01T20:26:57.326Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-04-23T22:31:04.805Z"},"title":"Kashipara Online Furniture Shopping Ecommerce Website search.php cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"CWE-79 Cross Site Scripting"}]}],"affected":[{"vendor":"Kashipara","product":"Online Furniture Shopping Ecommerce Website","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as problematic. Affected is an unknown function of the file search.php. The manipulation of the argument txtSearch leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-261798 is the identifier assigned to this vulnerability."},{"lang":"de","value":"Es wurde eine problematische Schwachstelle in Kashipara Online Furniture Shopping Ecommerce Website 1.0 ausgemacht. Dabei betrifft es einen unbekannter Codeteil der Datei search.php. Durch das Beeinflussen des Arguments txtSearch mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}}],"timeline":[{"time":"2024-04-23T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-04-23T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-04-23T15:46:07.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"SSL_Seven_Security Lab_WangZhiQiang_XiaoZiLong (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.261798","name":"VDB-261798 | Kashipara Online Furniture Shopping Ecommerce Website search.php cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.261798","name":"VDB-261798 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.321446","name":"Submit #321446 | kashipara Online Furniture Shopping Ecommerce Website Project ≤1.0 XSS injection","tags":["third-party-advisory"]},{"url":"https://github.com/E1CHO/cve_hub/blob/main/Online%20Furniture%20Shopping%20Ecommerce%20Website/Online%20Furniture%20Shopping%20Ecommerce%20Website%20Project%20-%20vuln%204.pdf","tags":["exploit"]}]},"adp":[{"affected":[{"vendor":"kashipara","product":"online_furniture_shopping_ecommerce_website","cpes":["cpe:2.3:a:kashipara:online_furniture_shopping_ecommerce_website:1.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1.0","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-15T20:02:27.076918Z","id":"CVE-2024-4072","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-16T14:57:24.856Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T20:26:57.326Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.261798","name":"VDB-261798 | Kashipara Online Furniture Shopping Ecommerce Website search.php cross site scripting","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.261798","name":"VDB-261798 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.321446","name":"Submit #321446 | kashipara Online Furniture Shopping Ecommerce Website Project ≤1.0 XSS injection","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/E1CHO/cve_hub/blob/main/Online%20Furniture%20Shopping%20Ecommerce%20Website/Online%20Furniture%20Shopping%20Ecommerce%20Website%20Project%20-%20vuln%204.pdf","tags":["exploit","x_transferred"]}]}]}}