CVE-2024-2996 is a Cross-Site Scripting (XSS) vulnerability affecting Bdtask Multi-Store Inventory Management System versions up to 20240320, specifically within an unknown function of the Page Title Handler component. Rated Medium severity (CVSS 4.8), it requires high privileges and user interaction for a remote attacker to achieve limited impact on confidentiality and integrity. While public exploit details exist, there is no evidence of active exploitation, and it has received minimal community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20240320CPE matchmatch criteria | cpe:2.3:a:bdtask:multi_store_inventory_management_system:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.