Cross Site Scripting Vulnerability in Record Management System 1.0
CVE-2024-8137
6.1MEDIUM
Key Information:
- Vendor
SourceCodester
- Status
- Vendor
- CVE Published:
- 24 August 2024
What is CVE-2024-8137?
A cross-site scripting (XSS) vulnerability has been identified in the SourceCodester Record Management System 1.0, specifically affecting the search_user.php file. The vulnerability arises from improper handling of user inputs in the search argument, allowing attackers to inject malicious scripts. This issue can be exploited remotely, posing a significant risk to users interacting with the affected system. Given that the exploit has been made public, immediate attention is necessary to mitigate the potential for unauthorized access and data leakage.