CVE-2024-3090Cross-site Scripting in Emergency Ambulance Hiring Portal

Severity
4.8MEDIUMNVD
CNA2.4
EPSS
0.1%
top 74.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30

Description

A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/add-ambulance.php of the component Add Ambulance Page. The manipulation of the argument Ambulance Reg No/Driver Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258683.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NExploitability: 1.7 | Impact: 2.7

🔴Vulnerability Details

2
CVEList
PHPGurukul Emergency Ambulance Hiring Portal Add Ambulance Page add-ambulance.php cross site scripting2024-03-30
GHSA
GHSA-v2cx-v2c6-w7xm: A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 12024-03-30
CVE-2024-3090 — Cross-site Scripting | cvebase