PT-2024-17870 · Unknown · Code-Projects Hospital Management System

Fergod

·

Published

2024-12-29

·

Updated

2024-12-29

·

CVE-2024-13012

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions code-projects Hostel Management System version 1.0
Description A problematic issue has been found in the processing of the file /admin/registration.php. The manipulation of the arguments fname, mname, and lname leads to cross-site scripting. The attack may be initiated remotely.
Recommendations For code-projects Hostel Management System version 1.0, consider disabling the processing of the fname, mname, and lname arguments in the /admin/registration.php file until a patch is available. Restrict access to the /admin/registration.php file to minimize the risk of exploitation. Avoid using the fname, mname, and lname arguments in the affected file until the issue is resolved.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-13012

Affected Products

Code-Projects Hospital Management System