Cross Site Scripting Vulnerability in Online Graduate Tracer System
CVE-2024-7844
5.4MEDIUM
Summary
A vulnerability has been identified in SourceCodester Online Graduate Tracer System version 1.0, specifically within the file /tracking/admin/add_acc.php. This issue stems from inadequate validation and insufficient sanitization of input parameters, allowing attackers to manipulate the arguments for name, user, or position. Such manipulation can lead to cross-site scripting (XSS) attacks, enabling external entities to execute malicious scripts within the context of the user's session. The vulnerability can be exploited remotely, and has been publicly disclosed, potentially impacting the security of the application's users.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Collectors
NVD Database