PT-2024-25196 · Sourcecodester · Sourcecodester Computer Laboratory Management System

Mohitkumar0786

·

Published

2024-05-01

·

Updated

2025-04-22

·

CVE-2024-33306

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester Laboratory Management System version 1.0
Description The issue is related to Cross Site Scripting (XSS) via the First Name parameter in the Create User function. This allows for potential malicious script injection.
Recommendations For SourceCodester Laboratory Management System version 1.0, as a temporary workaround, consider validating and sanitizing the First Name parameter to prevent XSS attacks until a patch is available. Restrict access to the Create User function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-33306

Affected Products

Sourcecodester Computer Laboratory Management System