CVE-2024-1871

Severity
5.4MEDIUM
EPSS
0.1%
top 72.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26

Description

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. Affected is an unknown function of the file /process/assignp.php of the component Project Assignment Report. The manipulation of the argument pname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-254694 is the identifier assigned to this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:NExploitability: 2.1 | Impact: 1.4

🔴Vulnerability Details

2
GHSA
GHSA-w98j-8492-h547: A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 12024-02-26
CVEList
SourceCodester Employee Management System Project Assignment Report assignp.php cross site scripting2024-02-24