PT-2024-18337 · Unknown · Phpgurukul Tourism Management System

Vishnudev1

·

Published

2024-02-23

·

Updated

2024-12-06

·

CVE-2024-1822

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Tourism Management System version 1.0
Description A problematic vulnerability has been found in the PHPGurukul Tourism Management System. The issue affects an unknown function of the file user-bookings.php, where the manipulation of the Full Name argument leads to cross-site scripting. This attack can be launched remotely. The exploit has been disclosed to the public.
Recommendations For PHPGurukul Tourism Management System version 1.0, consider disabling the user-bookings.php file or restricting access to it until a patch is available. As a temporary workaround, avoid using the Full Name argument in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1822

Affected Products

Phpgurukul Tourism Management System