CVE-2024-1197 – SourceCodester Testimonial Page Manager HTTP GET Request delete-testimonial.php sql injection
https://notcve.org/view.php?id=CVE-2024-1197
A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file delete-testimonial.php of the component HTTP GET Request Handler. The manipulation of the argument testimony leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-252695. • https://vuldb.com/?ctiid.252695 https://vuldb.com/?id.252695 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-1196 – SourceCodester Testimonial Page Manager HTTP POST Request add-testimonial.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-1196
A vulnerability classified as problematic was found in SourceCodester Testimonial Page Manager 1.0. This vulnerability affects unknown code of the file add-testimonial.php of the component HTTP POST Request Handler. The manipulation of the argument name/description/testimony leads to cross site scripting. The attack can be initiated remotely. VDB-252694 is the identifier assigned to this vulnerability. • https://vuldb.com/?ctiid.252694 https://vuldb.com/?id.252694 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •