Severity
4.8MEDIUM
EPSS
0.2%
top 53.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17

Description

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sscdms/classes/Users.php?f=save of the component HTTP POST Request Handler. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

🔴Vulnerability Details

2
CVEList
SourceCodester Student Study Center Desk Management System HTTP POST Request Users.php cross site scripting2024-07-17
GHSA
GHSA-r2jx-292h-wx26: A vulnerability was found in SourceCodester Student Study Center Desk Management System 12024-07-17
CVE-2024-6807 (MEDIUM CVSS 4.8) | A vulnerability was found in Source | cvebase.io