PT-2024-16582 · Unknown · Romadebrian Web-Sekolah

Romadebrian

·

Published

2024-11-05

·

Updated

2024-11-09

·

CVE-2024-10840

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions romadebrian WEB-Sekolah version 1.0
Description A vulnerability has been found in the file /Admin/akun edit.php of the component Backend. The manipulation of the argument kode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For romadebrian WEB-Sekolah version 1.0, update to the latest version to mitigate risks. As a temporary workaround, consider restricting access to the /Admin/akun edit.php file until a patch is available. Avoid using the argument kode in the affected backend component until the issue is resolved.

Exploit

Fix

Improper Neutralization

Special Elements Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-10840

Affected Products

Romadebrian Web-Sekolah