PT-2024-24145 · Unknown · Computer Laboratory Management System

Ayush Patidar

·

Published

2024-06-20

·

Updated

2024-07-03

·

CVE-2024-31586

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Computer Laboratory Management System version 1.0
Description A Cross Site Scripting (XSS) vulnerability exists, allowing a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters.
Recommendations For Computer Laboratory Management System version 1.0, consider restricting input for the Borrower Name, Department, and Remarks parameters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-31586

Affected Products

Computer Laboratory Management System