Cross Site Scripting Vulnerability in Record Management System 1.0
CVE-2024-8137

6.1MEDIUM

Key Information:

Vendor
CVE Published:
24 August 2024

Summary

A cross-site scripting (XSS) vulnerability has been identified in the SourceCodester Record Management System 1.0, specifically affecting the search_user.php file. The vulnerability arises from improper handling of user inputs in the search argument, allowing attackers to inject malicious scripts. This issue can be exploited remotely, posing a significant risk to users interacting with the affected system. Given that the exploit has been made public, immediate attention is necessary to mitigate the potential for unauthorized access and data leakage.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.