PT-2024-23710 · Unknown · Phpgurukul Complaint Management System

Published

2024-04-17

·

Updated

2025-04-10

·

CVE-2024-30989

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions phpgurukul Client Management System using PHP & MySQL version 1.1
Description The issue allows attackers to execute arbitrary code via the cname, comname, state, and city parameters in the "/edit-client-details.php" endpoint. This enables attackers to perform Cross Site Scripting attacks.
Recommendations For phpgurukul Client Management System using PHP & MySQL version 1.1, consider validating and sanitizing user input for the cname, comname, state, and city parameters to prevent arbitrary code execution. As a temporary workaround, restrict access to the "/edit-client-details.php" endpoint until a patch is available. Avoid using the cname, comname, state, and city parameters in the affected endpoint until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-30989

Affected Products

Phpgurukul Complaint Management System