CVE-2024-57522 is a cross-site scripting (XSS) vulnerability in SourceCodester Packers and Movers Management System version 1.0. The flaw exists in the Users.php file, where user-supplied input in the username or name fields during user creation is not properly sanitized, allowing attackers to inject malicious JavaScript code. This code can be executed in the context of another user's browser session when the affected data is viewed, leading to potential session hijacking or other client-side attacks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Proof of Concept (PoC) exploit for a stored Cross-Site Scripting (XSS) vulnerability (CVE-2024-57522) in SourceCodester Packers and Movers Management System 1.0. The main exploit file, 'CVE-2024-57523..html', is an HTML/JavaScript page that performs a Cross-Site Request Forgery (CSRF) attack against the vulnerable Users.php endpoint. When the user clicks the button, a crafted POST request is sent to 'http://localhost/mpms/classes/Users.php?f=save', creating a new user with attacker-controlled fields (including a stored XSS payload in the name fields). The README.md provides detailed context, including vulnerability description, affected product, attack vectors, and mitigation recommendations. The exploit demonstrates how an attacker can leverage CSRF to inject a persistent XSS payload, which is then executed in the admin's browser when viewing the user list. The repository is structured with a single exploit HTML file and a comprehensive README, and is intended as a PoC for security research and awareness.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.