PT-2024-22376 · Unknown · Sourcecodester School Task Manager

Published

2024-05-09

·

Updated

2025-02-11

·

CVE-2024-28277

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester School Task Manager version 1.0
Description A vulnerability was identified within the subject name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This issue allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.
Recommendations For Sourcecodester School Task Manager version 1.0, consider restricting access to the subject name= parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the subject name= parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28277

Affected Products

Sourcecodester School Task Manager