info: name:123Solar 1.8.4.5- Cross-Site Scripting author: ritikchaddha severity: medium description: | 123Solar 1.8.4.5 is vulnerable to reflected cross-site scripting (XSS) via the date1 parameter in detailed.php. Unsanitized user input is reflected in the response, allowing arbitrary JavaScript execution. impact: | Successful exploitation of this XSS vulnerability allows attackers to execute arbitrary JavaScript code in victims' browsers, potentially leading to session hijacking, credential theft, or other malicious activities. remediation: | Update 123Solar to the latest version. Implement proper input validation and output encoding for all user-supplied data, especially the date1 parameter in detailed.php. reference: - https://github.com/Hebing123/cve/issues/73 - https://nvd.nist.gov/vuln/detail/CVE-2024-9007 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N cvss-score:6.1 cve-id: CVE-2024-9007 cwe-id: CWE-79 cpe: cpe:2.3:a:123solar:123solar:1.8.4.5:*:*:*:*:*:*:* metadata: verified:true max-request:1 vendor:123solar product:123solar fofa-query: title="123Solar" shodan-query: title:"123Solar" tags: cve,cve2024,xss,123solar