Cross Site Scripting (XSS) Vulnerability in SystemSettings.php
CVE-2024-3377
Key Information:
- Vendor
- Sourcecodester
- Vendor
- CVE Published:
- 6 April 2024
Badges
Summary
A vulnerability exists in the SourceCodester Computer Laboratory Management System that enables remote attackers to inject malicious scripts via the 'name' argument during the update settings process. This cross-site scripting issue allows attackers to execute arbitrary JavaScript in the context of the user’s session, potentially compromising sensitive information and enabling unauthorized actions. The affected script is located at /classes/SystemSettings.php?f=update_settings, and the exploit has been publicly disclosed, highlighting the importance of immediate remediation to protect user data from potential threats.
Affected Version(s)
Computer Laboratory Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved