A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://code-projects.org/jonnys-liquor-in-php-css-javascript-and-mysql-free-download/ | product |
https://github.com/Akhlak2511/CVE-2024-50969 | third party advisory |