PT-2024-15426 · Unknown · Project Worlds Online Lawyer Management System

Harikrishnan

·

Published

2024-01-06

·

Updated

2025-08-28

·

CVE-2024-0266

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Project Worlds Online Lawyer Management System version 1.0
Description A vulnerability has been found in the User Registration component of the system. The manipulation of the First Name argument leads to cross-site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Project Worlds Online Lawyer Management System version 1.0, consider disabling the User Registration component until a patch is available. Restrict access to the First Name argument in the User Registration form to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-0266

Affected Products

Project Worlds Online Lawyer Management System