Cross Site Scripting Vulnerability in PHPGurukul Land Record System 1.0
CVE-2024-13075

5.3MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
31 December 2024

Summary

A cross site scripting vulnerability exists in PHPGurukul Land Record System 1.0, specifically within the code handling the '/admin/add-propertytype.php' file. This issue allows remote attackers to manipulate the 'Land Property Type' argument, which may result in unauthorized script execution in the context of the user’s browser. The exploitation of this vulnerability can compromise the confidentiality and integrity of data within the application, making it an essential concern for users of the system. The exploit has been publicly disclosed, raising the urgency for affected users to secure their applications against potential attacks.

Affected Version(s)

Land Record System 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Havook (VulDB User)
.