Cross-Site Scripting (XSS) vulnerability in /jobportal/index.php could allow attacker to retrieve session details of authenticated users
CVE-2024-8472
6.1MEDIUM
What is CVE-2024-8472?
A Cross-Site Scripting (XSS) vulnerability exists in the Job Portal Software, which fails to properly encrypt user-controlled input. This lack of encryption enables attackers to inject malicious scripts into web applications, giving them the potential to retrieve sensitive session details of authenticated users. The vulnerability can be exploited through multiple parameters, specifically in the /jobportal/index.php file, making it essential for users and administrators to immediately address this security flaw to protect user data.
Affected Version(s)
Job Portal 1.0