CVE-2024-34224

Severity
7.3HIGH
EPSS
0.8%
top 25.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:NExploitability: 2.1 | Impact: 5.2

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-m4gv-x9wg-r7pw: Cross Site Scripting vulnerability in /php-lms/classes/Users2024-05-14
CVEList
CVE-2024-34224: Cross Site Scripting vulnerability in /php-lms/classes/Users2024-05-13