CVE-2024-33981

C

ross-Site Scripting (XSS) vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'start' parameter in '/admin/mod_reports/index.php'.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:janobe:credit_card:1.0:*:*:*:*:*:*:*
cpe:2.3:a:janobe:debit_card_payment:1.0:*:*:*:*:*:*:*
cpe:2.3:a:janobe:paypal:1.0:*:*:*:*:*:*:*

History

15 Aug 2024, 14:08

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-06 11:16

Updated : 2024-08-15 14:08


NVD link : CVE-2024-33981

Mitre link : CVE-2024-33981

CVE.ORG link : CVE-2024-33981


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')