PT-2024-24173 · Unknown · Insurance Management System

Mohitkumar0786

·

Published

2024-04-15

·

Updated

2024-08-08

·

CVE-2024-31648

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Insurance Management System version 1.0
Description The issue allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at "/core/new category2". This enables attackers to perform Cross Site Scripting (XSS) attacks.
Recommendations For Insurance Management System version 1.0, consider disabling access to the "/core/new category2" endpoint until a patch is available, and restrict the use of the Category Name parameter to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-31648

Affected Products

Insurance Management System