XSS Vulnerability in /jobportal/process.php Could Expose Authenticated User Session Details
CVE-2024-8471

6.1MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
5 September 2024

Summary

This vulnerability is characterized as a Cross-Site Scripting (XSS) issue where user-controlled input is not adequately encrypted. An attacker can exploit this weakness to gain access to sensitive session details of authenticated users through specific parameters such as JOBID and USERNAME communicated via the /jobportal/process.php endpoint. Such exploitation poses a significant risk of session hijacking, which could lead to unauthorized access and manipulation of user accounts within the affected job portal software.

Affected Version(s)

Job Portal 1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Rafael Pedrero
.